Cybersecurity landscape in Vietnam – Q2/2026: Key risks and recommendations for businesses
- Evelyn Carter

- 1 day ago
- 8 min read
Vietnam's cybersecurity landscape - Q2/2026 continued to evolve in a complex manner throughout the second quarter of 2026, with numerous incidents involving cross-border online fraud, malware distribution, account compromise, money laundering, personal data trading, and digital impersonation across online platforms.
Key highlights
Online scams continued expanding in terms of targets, platforms, and attack methods.
Criminal networks increasingly operated across provinces and national borders, often involving money laundering and online gambling.
Personal data and bank accounts became valuable assets collected, traded, or exploited to facilitate cybercrime.
Malware, malicious files, and phishing links remained active within government agencies and enterprise environments.
Artificial Intelligence (AI) and deepfake technologies enabled faster, more convincing, and highly personalized impersonation attacks.
Cybercriminals are no longer targeting only individual accounts or one-time password (OTP) codes. Instead, they are increasingly focusing on controlling user accounts, financial transactions, personal data, and digital trust while leveraging social media, banking services, mobile applications, and online platforms to expand their operations.
To compare developments between reporting periods, businesses may also refer to the Vietnam Cybersecurity Landscape – Q1 2026.
I. Overview of Vietnam's cybersecurity landscape in Q2/2026
One notable observation is that many security incidents did not begin with sophisticated hacking techniques. Instead, attackers often exploited weak passwords, unpatched software, compromised accounts, or manipulated human psychology to persuade victims into voluntarily disclosing sensitive information or granting unauthorized access.
As a result, Vietnamese enterprises' cybersecurity posture depends on far more than the number of security solutions they have deployed. Effective cyber defense also relies on identity management, access control, endpoint monitoring, and well-defined incident response procedures.

1. April 2026: Key cybersecurity developments
Nhan Dan Newspaper's April 2026 cybersecurity update covered incidents occurring from the second half of March through the first half of April. During this period, law enforcement agencies handled numerous cases involving cross-border cyber fraud, malware distribution, fraudulent financial transactions, and illegal collection of personal information.
Key incidents included:
In Dien Bien Province, authorities dismantled a cross-border cyber fraud ring and arrested 55 suspects.
In Thanh Hoa Province, authorities uncovered a global malware distribution operation allegedly led by a twelfth-grade student.
In Bac Ninh Province, one individual was prosecuted for creating fake successful bank transfer confirmations to defraud customers of more than VND 2.1 billion.
In Hanoi, nine suspects were prosecuted for illegally collecting personal information to open bank accounts and sell them for profit.
Cyberattack capabilities are becoming increasingly accessible
Launching cyberattacks or distributing malware no longer requires membership in a long-established cybercrime organization. Individuals with relatively limited resources can now participate in sophisticated criminal activities.
Bank accounts and digital identities have become part of cybercriminal infrastructure
Leaked identification documents, phone numbers, facial images, or banking information can be exploited to create fraudulent bank accounts and facilitate money laundering activities.
Fake payment confirmations remain an effective fraud technique
Fraudsters can use fabricated banking interfaces or forged transfer confirmations to deceive both merchants and business personnel.
Businesses should verify that payments have actually been credited to their bank accounts rather than relying solely on screenshots, mobile notifications, or payment confirmations provided by customers.
April also marked a stronger emphasis on long-term prevention. On April 3, the "Students and Cybersecurity 2026" competition was launched to improve cybersecurity awareness and promote safer Internet usage among secondary school students.
2. May 2026: Cybercriminals target financial flows and digital trust
Nhan Dan Newspaper's May cybersecurity update summarized incidents that occurred between April 15 and May 15, 2026. According to the report, cybercrime has evolved beyond isolated online scams, reflecting a broader trend in which attackers seek to control user accounts, financial transactions, and public trust in digital environments.
Notable incidents included:
A woman in Hanoi lost nearly VND 1 billion after participating in fake "online task" schemes disguised as promotions from a well-known mother-and-baby retail brand.
Police in Ha Tinh Province dismantled a cross-border money laundering and online gambling network.
Authorities in Hung Yen Province arrested a criminal group operating online gaming scams.
In Ninh Binh Province, several suspects were prosecuted for opening multiple bank accounts used to facilitate online fraud and money laundering.
Hai Phong Police issued warnings about fake social media pages impersonating retail stores to steal deposits for mobile phones, computers, and watches.
The incidents reported in May demonstrate that intermediary bank accounts have become a critical component of cybercriminal operations. Bank accounts that are rented, purchased, or opened using someone else's identity help conceal financial transactions, split payment flows, and complicate criminal investigations.
For businesses, similar risks may arise when attackers:
Impersonate suppliers and request changes to payment information.
Compromise a partner's email account before sending new bank account details.
Create fake social media pages impersonating trusted brands to collect deposits.
Use bank accounts that do not match the legal entity specified in contracts.
Build websites or social media pages that closely resemble official corporate channels.
Businesses should establish independent verification procedures whenever payment information changes. Employees should never verify payment requests using the phone numbers or email addresses included within suspicious communications themselves.
3. June 2026: Online fraud, personal data, and multi-platform cybercrime
From late May to mid-June 2026, Nhan Dan Newspaper reported multiple incidents involving cross-border fraud, illegal streaming, gambling, forged documents, data trading, and lending schemes conducted through cloud accounts.
The reported incidents included:
An alleged plan to establish a cross-border fraud center in Phu Tho Province.
An illegal streaming and gambling network in Hung Yen Province.
A group in Bac Ninh Province accused of forging documents to fraudulently sell vehicles online.
A tenth-grade student accused of breaching the national vaccination system and offering approximately 20 million personal data records for sale.
A fraudulent prize-card scheme conducted through livestreams in Son La Province.
A group in Ninh Binh Province offering loans at annual interest rates of up to 608% through iCloud accounts.
The figure of 20 million personal data records relates only to the specific case mentioned in the report. It does not represent the total volume of leaked data across Vietnam during Q2 2026.
The incidents reported in June show that cybercriminals increasingly combine multiple platforms within a single operation: social media to approach victims, messaging applications to communicate, bank accounts to receive money, and cloud services to lock or control devices.
Businesses should train employees to identify AI-enabled scam tactics. However, awareness training should not be treated as the only line of defense. Sensitive transactions and unusual requests must also be verified independently.
II. Key takeaways from the cybersecurity landscape in Vietnam Q2/2026
The growing risk of personal data Intrusion and trading
The cases reported in April and June show that personal data can be exploited at several stages, including illegal collection, fraudulent bank account creation, money movement, and online resale.

Data-related risks may arise from:
Weak passwords or passwords reused across multiple systems.
Former employee accounts that have not been disabled.
Access privileges that exceed actual business needs.
Insecurely configured APIs or administrative portals.
Systems that have not been patched.
Data copied to unmanaged devices or services.
Insufficient logging to detect unusual data exports.
For this reason, enterprise data protection should begin by identifying which data is critical, where it is stored, who can access it, and which activities should trigger alerts.
Data encryption is an important control, but it cannot replace identity management, least-privilege access, and continuous monitoring of user activity.
Malware and malicious files remain present in organizational systems
Malware management system detected 419 devices across 68 organizations at risk of information security incidents during June 2026. The system recorded 427 malware and phishing-link threats, along with 4,223 malicious files. These figures apply only to Hai Phong and should not be interpreted as representative of Vietnam as a whole.
A device cannot be considered secure simply because antivirus software has been installed, especially when:
The security software is not regularly updated.
The device does not send logs to a centralized monitoring system.
Users are allowed to install software without restriction.
Alerts are generated but no one is assigned to investigate them.
The device remains connected to the network after showing signs of infection.
Businesses need to manage devices throughout their lifecycle, from deployment and use to patching and retirement. Devices that are no longer supported or cannot receive security updates should be isolated or replaced.
AI, deepfakes, and dutomation make attacks more convincing
Several trends, including software supply chain attacks, next-generation ransomware, and the use of AI to automate reconnaissance, personalize scams, and create deepfakes.
AI does not necessarily create entirely new categories of cybercrime. In many cases, it makes existing tactics faster, cheaper, and more convincing.
Attackers can use AI to:
Write context-aware emails with fewer language errors.
Imitate the communication style of company executives.
Generate fake voices from short audio samples.
Manipulate images or videos.
Personalize content based on a victim’s role and organization.
Interact automatically with many targets at the same time.
Businesses should not treat a voice, image, or video call as sufficient proof of identity. Requests involving money transfers, data disclosure, password resets, or administrator access should be verified through a second channel.

III. What does Vietnam’s cybersecurity landscape in Q2/2026 reveal?
The sequence of events from April to June shows that cybersecurity risk in Vietnam is no longer concentrated in a single technical layer. Attacks increasingly combine malware, account compromise, identity impersonation, psychological manipulation, intermediary bank accounts, and money laundering.
1. Cybercrime is increasingly operating as a chain
A single scam may involve several groups: one group collecting data, another creating fraudulent content, another contacting victims, another providing bank accounts, and another laundering the proceeds.
This explains why blocking a single link or freezing one account may not be enough to disrupt the entire criminal operation.
2. Digital identities and bank accounts have become criminal infrastructure
Cases involving accounts opened with stolen information, the use of multiple intermediary accounts, and compromised accounts show that digital identities are now direct targets.
Businesses need to manage not only passwords, but also account creation, access recovery, payment detail changes, and account revocation.
3. The line between cybersecurity and financial fraud is becoming increasingly blurred
Fake online tasks, fraudulent deposits through impersonated fan pages, forged payment confirmations, and money laundering operations show that financial losses often begin with an identity incident or a manipulated action on a digital platform.
For this reason, IT, finance, accounting, legal, and risk management teams need to coordinate rather than handle incidents separately.
4. Detection and response are as important as prevention
No organization can guarantee that every attack will be prevented. The ability to detect suspicious activity early, lock compromised accounts, isolate affected devices, and activate an incident response process will directly influence the scale of damage.
IV. IPSIP Vietnam's perspective
The cybersecurity landscape in Vietnam during Q2/2026 shows that businesses should no longer view cybersecurity solely as an IT issue.
The reported incidents indicate that a successful cyberattack often results from weaknesses across multiple areas, including identity management, operational processes, payment verification, employee awareness, and incident response.

Vietnam's cybersecurity landscape in Q2 2026 demonstrates that cyber threats are becoming more interconnected, more automated, and increasingly difficult to detect through traditional security measures alone. For businesses, cybersecurity is no longer solely about preventing attacks. It is equally about detecting suspicious activity early, responding quickly, protecting critical assets, and maintaining operational resilience.
Checklist: What should enterprises prioritize?
Based on the cybersecurity developments observed during Q2 2026, businesses should prioritize the following actions:
Review privileged accounts and remove unnecessary access rights.
Strengthen multi-factor authentication (MFA) for critical systems.
Establish independent verification procedures for payment information changes.
Improve monitoring of endpoints, servers, and cloud environments.
Develop and regularly test an incident response plan.
Conduct periodic cybersecurity awareness training for employees.
Perform regular cybersecurity assessments to identify vulnerabilities before they are exploited.
Organizations that continuously improve their cybersecurity posture are generally better prepared to respond to increasingly sophisticated attack methods.
For businesses, cybersecurity is no longer solely about preventing attacks. It is equally about detecting suspicious activity early, responding quickly, protecting critical assets, and maintaining operational resilience.
Building cybersecurity capabilities today is not only an investment in regulatory compliance but also an investment in business continuity and long-term digital trust.
References
Cybersecurity News - April 2026.: https://nhandan.vn/video-diem-tin-an-ninh-mang-thang-42026-post958376.html
Cybersecurity News – May 2026: https://nhandan.vn/video-diem-tin-an-ninh-mang-thang-52026-post964570.html
Cybersecurity News – June 2026: https://nhandan.vn/video-diem-tin-an-ninh-mang-thang-62026-post970690.html
Cybersecurity Law 2025: https://thitruongtaichinhtiente.vn/luat-an-ninh-mang-2025-buoc-dot-pha-chien-luoc-bao-ve-chu-quyen-so-quoc-gia-83976.html








Comments