Thailand found 60 million leaked credentials on the dark web. Takanori Nishiyama of Keeper Security explains why that matters here.
Thailand isn’t dealing with a single dramatic breach. It’s dealing with an accumulation. Officials from the country’s Digital Economy and Society Ministry say roughly 60 million additional Thai-linked credential records have built up on dark web markets over the past year, more than the country’s entire population, though many are duplicates or belong to the same person holding multiple accounts.
What makes the incident unusual isn’t the scale. It’s the method. According to reporting from Bangkok Post and Biometric Update, Thailand’s Interior Ministry found that criminals weren’t hacking their way in. They were buying stolen usernames and passwords from dark web marketplaces, then logging into government systems through ordinary application programming interfaces, the connections that let different software systems talk to each other, to pull out data. The underlying systems were never breached in the technical sense. The credentials just worked.
The fallout has reached senior levels of government. Personal data linked to Thailand’s prime minister and cabinet ministers has surfaced online, and data from more than 20 state agencies has been affected, according to Bangkok Post. In response, the Digital Economy and Society Ministry is preparing to seek cabinet approval for mandatory MFA across all government systems, alongside mass password resets and a review of roughly 30,000 government information systems to shut down old or abandoned ones still holding live access.
Why this isn’t just Thailand’s problem
Takanori Nishiyama, Senior Vice President APAC and Country Manager, Japan at password security firm Keeper Security, says the pattern points to a broader shift in how attackers operate. “Cybercriminals increasingly log in rather than break in,” he said. He pointed to Verizon’s 2026 Data Breach Investigations Report, which found credential abuse was the entry point in 25 per cent of breaches across the Asia-Pacific region, second only to exploiting software vulnerabilities at 42 per cent, and that stolen credentials showed up somewhere in the chain of 39 per cent of breaches globally, even when they weren’t the initial way in.
“The underlying systems were not directly breached,” Nishiyama said. “That distinction is the point: when valid credentials open the door, perimeter defences and even fully patched systems offer little protection.”
For Australian SME owners, the temptation is to file this under “not my problem, that’s government infrastructure.” But the mechanics don’t care about business size. A stolen password bought on a dark web marketplace works the same way against a five-person accounting firm’s cloud accounting login as it does against a Thai government API. Most small businesses run on the same kind of interconnected cloud systems, email, invoicing, customer databases, payment platforms, all reachable with nothing more than a username and password unless something extra is switched on.
Nishiyama argues the fix isn’t complicated, even if it requires discipline. “Security teams should treat identity as the primary control plane,” he said. “Enforcing multi-factor authentication everywhere, retiring dormant and orphaned accounts and applying least-privilege access ensures a single stolen credential cannot move laterally.”
That last phrase, least-privilege access, essentially means giving staff and software only the access they actually need, nothing more. Nishiyama also pointed to privileged access management, a category of tools that helps organisations remove standing access to sensitive systems, grant temporary access only when it’s needed, and monitor who’s using privileged accounts in real time. For most SMEs, the practical starting point is simpler: switch on MFA for every account that offers it, delete logins for former staff and unused services, and don’t assume a password alone is doing any real work.
“Thailand’s mandated password resets and system cleansing are sound first steps,” Nishiyama said. “Organisations should not wait for a breach of this scale to act. Audit who and what can access each system now, and make that review continuous.”
That last point is the one worth sitting with. Thailand’s response came after the damage was already public, cabinet ministers’ data circulating online, agencies scrambling to reset passwords under pressure. For a small business, an audit of who has access to what takes an afternoon, not a cabinet meeting.
Keep up to date with our stories on LinkedIn, Twitter, Facebook and Instagram.
