A leak of about 60 million Thai-linked credential records has pushed Thailand’s Digital Economy and Society Ministry to seek Cabinet backing for compulsory multi-factor authentication (MFA) across government systems, underscoring how stolen usernames and passwords — not system breaches — are now the primary route into critical networks across Asia-Pacific.
Data tied to senior officials and more than 500,000 citizen records has surfaced across at least 20 state agencies, according to Keeper Security, a password and privileged access management vendor tracking the incident. Criminals reportedly bought the stolen credentials on dark-web markets, then logged in through connected APIs to extract data — without breaching the underlying systems directly.
Credential abuse driving APAC breaches
The Thailand case reflects a broader regional pattern. Verizon’s 2026 Data Breach Investigations Report found that credential abuse was the initial access vector in a quarter of APAC breaches, second only to vulnerability exploitation, and featured across nearly two in five full breach chains globally.
- Credential abuse was the initial access vector in 25% of APAC breaches
- It appears across 39% of full breach chains globally
- Vulnerability exploitation remains the top vector at 42%
“Cybercriminals increasingly log in rather than break in… when valid credentials open the door, perimeter defences and even fully patched systems offer little protection,” said Takanori Nishiyama, Senior Vice President APAC and Country Manager, Japan, Keeper Security.
Nishiyama noted the conditions are not unique to Thailand. Japan holds similarly vast stores of citizen and enterprise data across interconnected systems and has faced its own credential-driven incidents, a dynamic reflected in the country’s Active Cyber Defense Law and broader shift toward zero-trust principles.
Identity as the new control plane
Nishiyama argues that security teams should treat identity, rather than the network perimeter, as the primary control plane going forward. That means enforcing MFA everywhere, retiring dormant and orphaned accounts, and applying least-privilege access so a single stolen credential cannot move laterally across a network.
“Organisations should not wait for a breach of this scale to act. Audit who and what can access each system now, and make that review continuous,” said Nishiyama.
Privileged access management (PAM) tools, he added, help organisations remove standing privileges, grant just-in-time access, and monitor privileged sessions in real time. Thailand’s mandated password resets and system cleansing are described as sound first steps, but ones that need to be paired with continuous access audits rather than one-off remediation.



Share your thoughts