Thailand seeks mandatory MFA over 60m leaked credentials

SUNDAY, AUGUST 09, 2026
Thailand seeks mandatory MFA over 60m leaked credentials

Thailand will seek Cabinet backing for mandatory MFA after 60 million more Thai-linked credential records accumulated on the dark web.

Thailand’s Digital Economy and Society Ministry is preparing to seek Cabinet backing to make multi-factor authentication compulsory across government systems after about 60 million additional Thai-linked credential records accumulated on dark-web markets over the past year.

The figure refers to credential records rather than 60 million individual victims, as the accumulated information may include old and new accounts as well as multiple or duplicate records belonging to the same users.

Digital Economy and Society Minister Chaichanok Chidchob said on Sunday (August 9) that the government regarded the protection of citizens’ information as a “national agenda”. Prime Minister and Interior Minister Anutin Charnvirakul had made the issue a priority and issued policy directions, he added.

The ministry is accelerating preparations to introduce mandatory multi-factor authentication, or MFA, and intends to submit the measure to the Cabinet as soon as possible.

It is also coordinating with the National Cyber Security Agency (NCSA) and the Personal Data Protection Committee (PDPC) to strengthen enforcement of the Personal Data Protection Act. Agencies that fail to introduce appropriate security safeguards within a reasonable period could face action under the law.

Stolen credentials used through connected APIs

Chaichanok said preliminary findings indicated that the latest exposure did not result from hackers directly breaching the underlying cybersecurity systems.

Thailand seeks mandatory MFA over 60m leaked credentials

Instead, those involved allegedly purchased compromised usernames and passwords on the dark web, where credentials stolen from systems around the world have accumulated and are traded.

“Once those responsible obtained the passwords, they could log in normally through APIs connected to the systems and extract the data,” he said. “The cybersecurity system itself was not breached.”

Thailand-linked login records held on dark-web markets now exceed the country’s population, Chaichanok said. Around 60 million more records had been added over the past year alone, although the total may include repeated credentials and several accounts belonging to the same person.

The ministry is working on longer-term structural changes, but Chaichanok said the immediate response would focus on password resets and removing accounts that were no longer needed.

He plans to present the risk figures to the Cabinet while encouraging members of the public and government personnel to change passwords used for email and other online systems.

“What everyone can do immediately is change their passwords for email logins and other systems,” he said. “Government agencies must also remove old user accounts that are no longer being used, such as accounts belonging to civil servants who have already left, to close this vulnerability.”

Chaichanok said affected databases would not necessarily need to be shut down when investigators found that the underlying security system had not been directly breached. Agencies should instead reset passwords and conduct “user cleansing” to remove dormant and unnecessary accounts.

Political data exposure raises security questions

The policy push follows the online circulation earlier in the week of personal records linked to Anutin, Cabinet ministers and senior Interior Ministry officials. The exposed material was reported to include personal information and photographs taken from national identity cards.

Cybersecurity expert Thanarat Kuawattanaphan said information associated with the Department of Provincial Administration had been traced to the department’s own website. The exposure prompted concern over whether the security of government systems holding civil-registration information had been compromised.

The Department of Provincial Administration, however, said its preliminary investigation had found no evidence that information had leaked from the core civil-registration database. The Interior Ministry and the department were continuing to trace the route used to access the records.

The government’s preliminary inquiry similarly found no evidence that a government database had been directly hacked. Authorities closed the access channels involved and began digital-forensics examinations to establish the cause and identify those responsible.

Police trace digital trail and seize server

Chaichanok said ministry officials and cyber police had traced the digital trail and identified IP addresses and telephone numbers used in connection with the access.

Investigators had also seized a server allegedly used to cross-check the information after it was extracted and before it was offered for sale.

Police were continuing efforts to identify the individuals involved. Chaichanok said he had instructed both the ministry and its legal teams to pursue legal proceedings against those responsible to the fullest extent.