---
title: Thales FIDO Security Key addresses phishing risks in Thai government MFA rollout
url: https://www.dataloco.com/en/thales-fido-security-key-addresses-phishing-risks-in-thai-government-mfa-rollout
published: 2026-09-20T15:21:05+00:00
language: en
section: Security
source: https://www.techtalkthai.com/how-thales-phishing-resistant-mfa-can-prevent-data-breach/
organizations: Thales, National Cybersecurity Committee, KuppingerCole
publisher: Dataloco
---

# Thales FIDO Security Key addresses phishing risks in Thai government MFA rollout

Thales has introduced a FIDO Security Key solution designed to provide phishing-resistant multi-factor authentication for organizations in Thailand. This hardware device supports both FIDO2 and PKI certificate-based authentication, allowing enterprises to secure modern cloud applications and legacy systems within a single tool. The product aims to facilitate a transition toward passwordless identity verification while maintaining compatibility with existing infrastructure.

The deployment of this technology follows a significant data breach involving Thai government agencies. The incident exposed over 200 million username and password records to the public. This leak demonstrated that stolen credentials could be used to access systems without further intrusion, highlighting the limitations of single-factor password protection. In response, the National Cybersecurity Committee was tasked with promoting the adoption of multi-factor authentication across all state agencies to enhance the protection of critical systems and data.

Traditional multi-factor authentication methods, such as SMS codes, one-time passwords, and push notifications, remain vulnerable to social engineering attacks. Threat actors can use phishing, SIM swapping, and adversary-in-the-middle techniques to trick users into revealing codes or approving unauthorized logins. MFA fatigue and push bombing further exploit these weaknesses. Consequently, the presence of multi-factor authentication does not guarantee immunity against phishing attacks if the underlying mechanism relies on secrets that can be intercepted or coerced from the user.

The FIDO standard addresses these vulnerabilities by shifting from shared secrets to public key cryptography. In this model, a private key remains on the user's device, such as a smartphone or a hardware security key, while the service provider stores only the public key. Users verify their identity using a PIN or biometrics on their own device. This architecture prevents the transmission of private keys to servers, reducing the risk of credential theft, credential stuffing, and replay attacks. The login data is bound to the specific service, which mitigates the risk of phishing sites and the reuse of stolen credentials.

Passkeys, which utilize the FIDO standard, allow users to log in without traditional passwords. They support familiar verification methods like fingerprints, facial recognition, or device PINs. Passkeys can be synced across ecosystems or bound to specific hardware security keys. This flexibility enables organizations to select the appropriate level of security based on risk and operational context, reducing the burden of memorizing complex passwords while improving security posture.

Large organizations often face challenges when adopting new identity standards because legacy applications may still rely on PKI certificate-based authentication for network logon, digital signing, and encryption. Thales proposes a combined approach that integrates FIDO and PKI capabilities. This strategy allows new applications to move toward passwordless authentication while legacy systems continue to operate securely. The Thales FIDO Security Key and Fusion Token support both FIDO2 and PKI in a single device, simplifying the management of authenticators for IT teams.

The solution supports platforms that utilize FIDO2 and WebAuthn, including Microsoft Entra ID. It covers use cases such as digital signing, data protection, network logon, and remote access. By consolidating these functions, the device reduces the complexity of identity management. Organizations are advised to prioritize high-risk users and critical business systems, such as executive accounts, email, VPN, and privileged access, for the initial adoption of phishing-resistant multi-factor authentication. This phased approach moves identity security from basic multi-factor authentication to robust, phishing-resistant frameworks.

## This story in other languages

- [Português (Brasil)](https://www.dataloco.com/pt-br/thales-promove-mfa-resistente-a-phishing-apos-vazamento-de-dados)
