CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
privacy

Your Password Is Already for Sale. Here's the 4-Minute Fix.

Your Password Is Already for Sale. Here's the 4-Minute Fix.

Somewhere right now, your password is probably for sale. Not because you did anything wrong. Not because you clicked a bad link. Just because you've had accounts online for years — and at some point, one of those services got breached, and your password ended up in a list that criminals buy and sell the way other people trade baseball cards.

TL;DR

Thailand just made two-step login (MFA) mandatory after 60 million credentials leaked onto the dark web — and the stat that should change your mind about skipping it: MFA blocks 98.6% of attacks on accounts with already-stolen passwords.

Thailand just learned this the hard way. More than 60 million stolen login credentials tied to Thai government and private-sector accounts turned up on dark web marketplaces — those are underground online markets where stolen data gets bought and sold, invisible to regular search engines. The country's cybersecurity agency found over 200 million instances of leaked user data connected to Thailand. That number is larger than the country's entire population. It means years of slow, steady password theft finally hit a breaking point.

The Thai government's response? No more asking nicely. Biometric Update reports that Thailand is now pushing mandatory MFA — multi-factor authentication (that's the second login step, like a text code or an app notification sent to your phone after you type your password) — across government systems and pushing it hard into the private sector too.

The Part That Should Make You Stop Scrolling

Here's what's wild about how this breach actually worked. Criminals didn't break down any doors. There was no dramatic Hollywood hack. They just... logged in. They bought the stolen passwords, typed them into normal login pages, and got right in — because the systems had no second check. No "wait, is this really you?" moment. Just: password accepted, door open, come on through.

That's the real story here. The systems weren't broken. The passwords were.

94%
of the 19 billion passwords leaked in recent years were reused or duplicated across multiple accounts
Source: SQ Magazine

Read that again. Ninety-four percent. Almost every leaked password out there is one somebody used on more than one account. Which means if your email password leaked from some retail site you barely remember signing up for in 2019, anyone who bought that list now has a decent shot at your bank. Your work login. Your streaming services. Your health portal. One leaked password isn't one problem — it's a skeleton key. This article is part of a series — start with Europe Now Scans Your Face At The Border And Keeps It For 3 .

Why a Text Code Changes Everything

This is where MFA goes from annoying to genuinely important. Think of your password as the key to your front door. Now imagine someone made a copy of that key without you knowing. MFA is like adding a deadbolt that only opens when your phone buzzes and you tap "yes." Even if a criminal has the copied key, they're still locked out — because they don't have your phone.

"Even as credential leak volume climbed, compromised credentials fell from 31% to 22% as an initial breach vector — multi-factor authentication and passkeys are absorbing the defensive load." Vectra AI, threat intelligence analysis

Translation: more passwords are getting stolen than ever before, but fewer of those thefts are turning into actual account break-ins. Something is working. That something is the extra login step most of us find annoying.

How effective is it, exactly? Peer-reviewed research puts the number at 98.6% — that's the share of attacks on accounts with already-compromised passwords that MFA stops cold. Google ran its own study and found MFA blocked 100% of automated attacks (the kind bots run at scale, trying millions of passwords per hour) and 96% of mass phishing attempts. Those numbers haven't budged in years. The defense works.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

So Why Isn't Everyone Already Using It?

Honestly? Because it's a small pain in the moment. You're trying to log into something quickly, and now you have to wait for a text, or open an app, or find your phone that slid under the couch cushion. In that moment, you remember every time MFA slowed you down. You don't remember the thousand times it quietly kept someone out of your account, because that's invisible — it just... didn't happen.

That's a well-documented mental quirk called the availability heuristic — our brains weigh risks based on what we can easily remember, not on what's statistically likely. The one time you got locked out of your own account because your phone was dead? Vivid. The cyberattack that didn't happen while you were asleep? Zero memory of it, because there's nothing to remember.

Companies have been betting on this for years. "Make it optional, don't push users too hard, let them opt in." The result? According to industry research compiled by We Make Tech Simple, more than half of organizations still leave at least one major application completely unprotected by MFA. That's exactly where attackers go first. They look for the unlocked window. Previously in this series: That Shocking Photo Of Your Kid Check The Sender Before The .

Why This Matters to You Specifically

  • Your old passwords are probably already out there — 1.8 billion credentials were harvested in just the first half of 2025 alone, according to Vectra AI threat intelligence
  • 📊 Reused passwords multiply the damage — if you've ever used the same password on two different sites (most of us have), one breach becomes many
  • 🔒 MFA is the gap between "stolen password" and "stolen account" — and it's the gap that Thailand just decided to make mandatory for everyone
  • 💸 A breach that hits you personally costs far more than inconvenience — the average cost of cleaning up a data breach at an organizational level runs $4.67 million and takes 292 days to fully contain

The Real Debate: Should Companies Wait for You to Decide?

Thailand's move raises a genuinely interesting question, and it's not a comfortable one. If a government knows that 60 million of its citizens' passwords are already for sale — right now, today — is it ethical to leave the decision to turn on extra protection up to each individual user?

The Bangkok Post reporting on Thailand's response makes clear this wasn't a panicked overreaction. It was an acknowledgment that persuasion had already failed. Years of "we encourage you to enable two-step verification" produced exactly the outcome you'd expect: people who already cared turned it on, and everyone else didn't. The attackers focused on everyone else.

The counterargument is real, and it's worth taking seriously. Forcing MFA on people overnight causes chaos. Workers write codes on sticky notes stuck to their monitors (which defeats the purpose entirely). Older users get locked out of systems they depend on. Businesses that weren't ready for the transition break workflows that took years to build. Implementation without a proper runway isn't security — it's just a different kind of mess.

But here's the thing Thailand seems to have decided: a messy rollout that frustrates people for a few weeks is recoverable. A credential breach affecting 200 million records, accumulated quietly over years while companies waited for voluntary adoption, is not.

And the rest of the world isn't waiting anymore either. PCI DSS — the security standard that governs how companies handle your credit and debit card data — now requires strict MFA and behavioral monitoring (that's software that watches for unusual login patterns, like someone logging into your bank account from Bangkok when you live in Ohio) as mandatory for 2026. Microsoft and Google have been quietly requiring MFA for business accounts. Cyber insurance companies — the ones businesses pay to cover losses from hacks — are now making MFA a condition of getting coverage at all. If you don't have it, you can't get the insurance.

Thailand didn't invent this shift. They just put a flag in the ground and said: we're not asking anymore. Up next: Locked Phone Sms Privacy Gap.

Key Takeaway

Your password is probably already compromised somewhere. MFA — the second login check — is the one thing standing between a stolen password and a stolen account. If any service you use offers it, turn it on now. Don't wait to be forced. You won't remember doing it, and that's exactly the point: the attacks you never knew about are the ones it stopped.

The One Thing You Can Do Tonight

Open the settings on your most important accounts — your bank, your email, anywhere you store payment information — and look for "two-step verification" or "two-factor authentication." Turn it on. Set it up with an app like Google Authenticator or your phone's built-in system rather than just a text message if you can (text codes are better than nothing, but app codes are harder for criminals to intercept). It takes about four minutes.

That's it. Four minutes, and you've closed the gap that 60 million Thai credentials left wide open. You don't need to understand the technical details. You don't need to follow policy debates in Bangkok. You just need to add the deadbolt before someone with a copied key tries your door.

One more thing worth sitting with: the reason Thailand is making this mandatory isn't because Thai citizens are careless. It's because voluntary security has a predictable failure mode — the people most at risk are often the least likely to know they're at risk. If we only protect the people who already know enough to protect themselves, we're not really solving the problem. We're just deciding who gets left behind.

The uncomfortable question Thailand just forced into public debate isn't "is MFA annoying?" We all know it's annoying. The question is: once you know that someone's password is already for sale, whose job is it to add the second lock?

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search