
Thailand’s Ministry of Digital Economy and Society is accelerating efforts to address data leaks, with short-term measures due to be submitted to the Cabinet on August 11 alongside plans for a broader overhaul of the country’s data-security systems.
Digital Economy and Society Minister Chaichanok Chidchob said the ministry had gathered information to assess the structure, sources and system vulnerabilities associated with leaked data, giving authorities a clearer picture of the scale of the problem.
The assessment found approximately 56 billion exposed login records worldwide, including about 221 million records linked to Thailand.
In the government sector, about 30,000 systems were found to be associated with leaked login information, while more than 35,000 private-sector systems were linked to exposed data.
The findings show that the problem is not confined to government agencies and will require cooperation across the public and private sectors, Chaichanok said.
The most urgent measure is to reset or change potentially compromised login credentials so that information already exposed cannot be reused to gain access to systems.
Chaichanok described the move as a short-term measure intended to “buy time” while the government addresses deeper and more complicated weaknesses across the country’s digital infrastructure.
A full clean-up of affected systems will also be required because resetting login details alone is not a long-term solution. Agencies responsible for critical systems and sensitive information must simultaneously strengthen their security arrangements.
The ministry plans to convene relevant government ministries and departments, bringing together officials responsible for digital systems and technical specialists to conduct comprehensive assessments.
They will be asked to prepare plans and establish long-term measures to close vulnerabilities and prevent further data leaks.
Chaichanok said the effort would have to be carried out nationwide because large volumes of data had been exposed in both the public and private sectors.
The immediate priority should be for individuals and organisations to reset affected login credentials, while agencies and companies managing important systems or sensitive data upgrade their security at the same time, he added.
One of the main proposals to be presented to the Cabinet is an upgrade to the authentication systems used by government agencies, particularly those operating critical services.
The proposal would replace reliance on a username and password alone with multi-factor authentication, or MFA.
Air Vice Marshal Amorn Chomchoey, secretary-general of the National Cyber Security Agency, said single-layer password protection was no longer sufficient, particularly when such large volumes of account information had already been exposed.
Attackers can also use automated systems and artificial intelligence to make cyberattacks faster and more effective, increasing the risk that leaked credentials could be used to breach government systems.
Under the measure due to be proposed on August 11, critical state systems would be required to use at least two forms of identity verification.
This could involve combining a password with an additional method such as the ThaiD digital identity system or a one-time password, commonly known as an OTP.
The additional verification layer would make it more difficult for hackers to enter a system directly using previously exposed usernames and passwords.
Chaichanok said the latest meeting had also received information and recommendations from members of the public concerning possible sources of leaked data, the channels through which information may have been exposed and the ways in which malicious actors could exploit it.
Participants also proposed additional forms of cooperation needed from government agencies.
However, some details could not be disclosed because they related to investigative procedures and the protection of digital systems.
Relevant agencies will now examine the recommendations in greater detail, focusing first on short-term measures that can be submitted to the Cabinet on August 11.
The government will then hold a wider meeting of state agencies to develop a long-term plan for strengthening cybersecurity, upgrading authentication and closing vulnerabilities across the country’s information systems.