- What: Thailand plans mandatory MFA after a data leak.
- Impact: Affects government systems and user credentials.
Identity Thailand plans mandatory multi-factor authentication after massive data leak August 12, 2026 Share By SC Staff Biometric Update reports that Thailand is moving towards making multi-factor authentication a mandatory policy following the exposure of approximately 60 million credential records on the dark web. The Digital Economy and Society Minister is seeking cabinet approval for compulsory multi-factor authentication across all government systems. This initiative comes after a significant data leak, with around 60 million additional credentials appearing on the dark web in the past year, exceeding the country's population. The Interior Ministry attributes these leaks to criminals purchasing passwords from dark-web marketplaces and using them to log in through normal system APIs, rather than direct system breaches. In response, the ministry is implementing mass password resets and deleting dormant user accounts. Civil servants and the public are urged to change passwords for various online services. The data leak reportedly included personal information linked to high-ranking officials and information from national ID cards, raising concerns about civil registration systems. While preliminary checks indicate no breach of the core database, authorities are pursuing legal action against those responsible and have seized a server allegedly used for cross-checking stolen data. Thailand is also advancing its Digital ID 2.0 initiative and expanding its digital trust framework. Source: Biometric Update SC Staff Related AI/ML Who owns the agent? Identity governance for autonomous AI Paul Wagenseil August 12, 2026 Here's why AI agents must be treated as a new type of identity -- yet always must be tied to a human. Identity Cybercriminal caught after face-changing software glitch exposes identity SC Staff August 11, 2026 The unnamed man targeted a security company authorized to issue digital certificates, a process crucial for online authentication and legally recognized electronic signatures in Spain and other EU countries. Identity Windows Hello for Business keys can be silently abused by malware SC Staff August 10, 2026 Researcher Dirk-jan Mollema demonstrated that malware can exploit Windows Hello for Business keys on TPM-backed systems without extracting private keys, recovering PINs, or triggering biometric prompts. Related Events Cybercast Building the Future of Trust in the AI Era & AI-First Headless Identity Let’s You Build with AI Wed Sep 2 Cybercast The Future of Identity: Powering Trust in the AI Era & Fireside Chat with LPL Financial Tue Sep 1 Cybercast The identity evolution that enables AI confidence On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds