Get all your news in one place.
100's of premium titles.
One app.
Start reading
Bangkok Post
Bangkok Post
National

Government-wide password resets ordered after data leak

The government has ordered staff of more than 300 departments to reset passwords immediately and inspect 30,000 systems to prevent further state data leaks.

Government spokeswoman Rachada Dhnadirek said on Wednesday the cabinet had approved three measures proposed by the National Cyber Security Committee (NCSC) to strengthen protection against cyber threats and reduce the risk of personal data breaches.

The first measure, Force Reset Password, requires civil servants and staff across more than 300 departments to change their passwords immediately. The move is intended to prevent attackers from using previously leaked credentials to impersonate legitimate users and gain access to government systems.

The second, System Cleansing, requires ministries and departments to inspect more than 30,000 information systems within 15 days.

"Old or abandoned systems that are no longer in use must have their back-end access permanently disabled, as some agencies had closed public-facing websites while leaving back-end systems accessible," she said.

The third measure requires government systems to adopt multi-factor authentication (MFA), including the Digital Identity system known as the ThaID app operated by the Department of Provincial Administration (DOPA) or other secure authentication methods.

The measures were approved at the cabinet meeting chaired by Prime Minister and Interior Minister Anutin Charnvirakul on Tuesday, following a cyber-security meeting on Monday.

The NCSC said the measures were necessary after the Thailand Computer Emergency Response Team (ThaiCERT) detected more than 16,520 files, totalling about 5 terabytes, containing stolen credentials being circulated on Telegram, she said.

The data included email addresses, websites and passwords for government systems, with some credentials belonging to system administrators.

A review of Thai domains found 221,947,958 records covering government agencies, companies, education outlets, non-profit organisations and military agencies.

The NCSC identified several causes of credential leaks, including phishing, malware and keyloggers, insecure storage of credentials, and internal leaks.

The committee also highlighted password reuse, where the same password is used across multiple systems, meaning a breach of one system can expose access to others.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.