BANGKOK, Thailand (Aug 2026) – Cybercriminals did not even have to hack through complex firewalls to expose 60 million user accounts in a recent massive data spill. Instead, they simply bought stolen usernames and passwords on dark web markets and walked right through the front door using connected application programming interfaces.
Thailand’s Digital Economy and Society Ministry is now pushing for mandatory Multi-Factor Authentication (MFA) across all government systems after credential records tied to over 500,000 citizens and senior officials across at least 20 state agencies surfaced online.
Cybersecurity expert Takanori Nishiyama, Senior Vice President APAC and Country Manager for Japan at Keeper Security, highlighted that identity has officially become the main security control plane as credential abuse surges across the region.
Logging in instead of breaking in
According to the Verizon 2026 Data Breach Investigations Report, credential abuse was the entry point in 25% of breaches across the Asia-Pacific region, making it the second most common attack method behind vulnerability exploitation at 42%. Globally, stolen credentials appear in 39% of all full breach chains.
When valid usernames and passwords fall into the wrong hands, traditional perimeter defenses offer little protection because attackers log into systems cleanly without triggering security alarms.
A warning for the region
The risk is not unique to one nation. Enterprise networks and government agencies across Asia store vast amounts of citizen and customer data across interconnected systems, making them prime targets for credential-based attacks.
Countries like Japan have responded to similar threats through policy shifts, including the Active Cyber Defense Law and zero-trust framework adoption. These moves reflect a growing consensus: static passwords alone can no longer protect critical systems.
Simple steps to lock down access
To prevent a single stolen password from allowing unauthorized lateral movement across a network, Keeper Security recommends several steps for IT and security teams:
- Require multi-factor authentication across every application and system.
- Audit systems regularly to remove dormant and orphaned accounts.
- Apply least-privilege access controls so users only reach data necessary for their specific role.
- Implement Privileged Access Management to grant just-in-time access and monitor active sessions in real time.
Security teams should audit who and what can access each system continuously rather than waiting for a major breach to act.
