top of page

Cybersecurity Weekly News (14/9–20/9): Malware Hidden in Documents, Billion-VND Fraud and AI-Accelerated Attacks

2 days ago
6 min read

Cybersecurity Weekly News for September 14–20, 2026 highlights several notable developments in Vietnam, from malware hidden in Word and PDF files compromising more than 12,400 computers to an online fraud network involving more than VND 1 trillion, changes in the cybersecurity governance structure, and hands-on cyber exercises at the local level.

Internationally, AI Agents and phishing campaigns targeting Cloud environments continued to reduce the time organizations have to detect and respond to threats.

Key developments this week included malware distributed through recruitment content on LinkedIn and Facebook, a major cyber-enabled fraud and money-laundering case in Quang Ninh, warnings about AI Agents automating multiple stages of an attack chain, phishing campaigns targeting Microsoft Cloud accounts, and a supply-chain incident involving Brevo.

👉 Businesses can follow additional developments in the IPSIP cybersecurity news

I. Cybersecurity news in Vietnam

1. Malware hidden in word and PDF files compromised more than 12,400 computers

On September 16, 2026, the Ho Chi Minh City People’s Court heard a case involving a group that developed and distributed malware hidden inside seemingly legitimate Word and PDF files.

The attackers used recruitment and advertising content on LinkedIn and Facebook to persuade users to download and open infected documents.

According to case records, more than 12,480 computers across around 90 countries were compromised, including 125 systems in Vietnam. The malware was initially used to steal Facebook advertising account information and was later expanded to enable remote control of infected devices.

malware-hidden-in-word-and-pdf-files
Malware hidden in word and PDF files

The key issue was not the Word or PDF format itself, but the attacker’s ability to place malicious files in a context that appeared familiar and trustworthy.

For businesses, this attack model is particularly relevant to HR, sales, marketing and accounting teams, which routinely receive CVs, quotations, contracts and other external documents.

Recommended action: Businesses should deploy EDR/antimalware, sandbox suspicious attachments, restrict execution privileges on endpoints and strengthen controls over externally downloaded files. Employees should also receive practical training on phishing and Social Engineering.

IPSIP Vietnam provides additional guidance in its article on cybersecurity awareness training for employees

2. Quang Ninh police dismantle online fraud network involving more than VND 1 trillion

On September 14, 2026, Vietnam’s Ministry of Public Security reported that Quang Ninh police had dismantled a network involved in online fraud, illegal trading of personal data and money laundering.

The investigation began with reports from eight citizens and later expanded into a case involving 21 defendants.

The suspects were investigated for multiple offenses, including fraud, the use of computer networks and electronic means to misappropriate assets, money laundering and the illegal trading of bank account information.

Authorities said the total amount involved exceeded VND 1 trillion.

The case shows that cyber-enabled fraud increasingly operates as an interconnected ecosystem. Personal data, bank accounts, Social Engineering and money flows can all form part of a larger criminal chain.

Recommended action: Businesses should require out-of-band verification for unusual financial requests, restrict who can modify payment information and monitor suspicious transaction patterns. Customer and employee accounts should also be protected with MFA, Least Privilege and comprehensive logging.

IPSIP Vietnam has covered similar risks in its article on brand impersonation and asset theft

3. Hanoi Police highlights Decree 327/2026/ND-CP on handling cyber threats

During the week, Hanoi Police continued to publicize Decree 327/2026/ND-CP, which covers the prevention and handling of information and activities involving information technology, computer networks, telecommunications networks and electronic means that threaten national security, public order and social safety in cyberspace.

The decree was issued by the Government and took effect on August 19, 2026.

For businesses, the practical implication is that digital systems must not only be technically secure, but should also support traceability, investigation and coordination when incidents or official requests arise.

Recommended action: Businesses should review log-retention periods, timestamp synchronization, access permissions for system logs and escalation procedures for suspected violations. Organizations improving their compliance framework can also refer to IPSIP’s guide on Cybersecurity Law compliance for businesses.

4. Vietnam’s cybersecurity authority officially adopts a new name from September 15

From September 15, 2026, the Department of Cybersecurity and High-Tech Crime Prevention officially became the Cybersecurity Department under the Ministry of Public Security’s updated organizational structure.

This was not a cyber incident, but it was a notable institutional development during a period when several new cybersecurity regulations were being implemented.

Recommended action: Businesses, especially those operating in critical or highly regulated sectors, should update legal contacts, incident-reporting responsibilities and escalation procedures. Incident Response Plans should include both technical and legal workflows instead of leaving the entire process to the IT team.

5. An Giang conducts hands-on cybersecurity exercise in 2026

On September 14, 2026, An Giang Provincial Police launched a practical cybersecurity exercise involving specialist units, local departments and relevant agencies.

The exercise highlights an important point: incident readiness cannot be assessed only through documentation or policies on paper.

During a real incident, organizations need to know who has authority to isolate systems, who preserves logs, who communicates with customers and who decides when systems can return to operation.

Recommended action: Businesses should conduct tabletop exercises, purple-team exercises or Incident Response drills on a regular basis. Scenarios should test detection, containment, evidence preservation and recovery.

II. International cybersecurity news

6. AI Agents can automate multiple stages of a cyberattack

During September 14–20, IPSIP Vietnam published an analysis of how AI Agents are moving beyond assisting with code generation or technical analysis and beginning to participate directly in multiple stages of an attack chain.

When connected to terminals, browsers, APIs or security tools, AI Agents can perform reconnaissance, exploitation, credential collection, lateral movement and data processing with less direct human supervision.

warning-ai-agent-in-cyberattack
AI Agents can automate multiple stages of a cyberattack

The key risk is not that AI creates completely new attack techniques, but that it can automate familiar techniques at greater speed and scale.

Recommended action: Businesses should manage internal AI Agents as privileged digital entities. Access to production systems, source code, cloud consoles, credentials and the Internet should follow Least Privilege. Agent activity should also be logged and auditable. IPSIP provides further guidance in its article on cybersecurity risk management in the AI era.

7. AI and fake “Passkey update” requests used to take over Microsoft Cloud accounts

IPSIP Vietnam also published a warning during the week about two campaigns targeting enterprise Microsoft Cloud users.

One scenario used AI to impersonate senior executives or create more convincing messages, while another relied on fake “Passkey update” requests to trick victims into granting access or disclosing authentication information.

The article highlights how AI can strengthen Social Engineering, while the underlying weakness remains the same: a user receives a request that appears legitimate and acts before independently verifying it.

Recommended action: Businesses should deploy phishing-resistant MFA such as FIDO2/WebAuthn, Conditional Access and out-of-band verification for sensitive account requests. Suspicious sign-ins should be actively monitored, and any email requesting a Passkey update, account re-verification or login via an embedded link should be verified independently before action is taken.

8. Brevo supply-chain attack injected malicious scripts into customer websites

On September 17, 2026, Brevo confirmed a supply-chain attack involving a compromised Cloudflare API key.

The attacker used that access to modify content at the CDN edge and inject ClickFix scripts into Brevo’s own website as well as JavaScript components embedded on customer websites.

The significant point is that the attacker did not need to compromise each customer individually.

By compromising a trusted intermediary used by multiple downstream websites, the attacker could potentially extend the impact across a wider ecosystem.

Recommended action: Businesses should integrate secrets scanning into CI/CD pipelines, avoid hardcoding API keys, apply Least Privilege to tokens and rotate secrets regularly. For third-party JavaScript, Content Security Policy and Subresource Integrity should be considered where appropriate. IPSIP provides additional context in its article on software supply-chain attacks.

III.  What should businesses prioritize after September 14–20?

This week’s developments highlight four major trends.

  • First, Social Engineering remains one of the most effective ways to bypass technical defenses. A legitimate-looking file, recruitment message or Passkey update request can become the starting point of an attack.

  • Second, data, identity and logging are becoming increasingly connected to corporate governance responsibilities. When an incident occurs, organizations need to know who accessed what, which actions were taken and what data may have been affected.

  • Third, supply chains and legitimate infrastructure are increasingly being abused a

  • \s trusted channels. A stolen API key, embedded script or cloud platform can help attackers bypass reputation-based controls.

  • Finally, AI is compressing attack timelines. Tasks that previously required more manual effort can increasingly be coordinated by Agents, making detection and response speed more important.

IPSIP Vietnam's expert perspective

TThe cybersecurity landscape during September 14–20, 2026 shows that cyber risk is no longer limited to newly discovered vulnerabilities.

A document sent in the right context, a traded bank account, an overprivileged AI Agent or an exposed API key can all become the starting point of a serious incident.

ipsip-viet-man-cybersecurity-solutions
IPSIP Vietnam cybersecurity solutions

For Vietnamese businesses, the priority should move beyond simply deploying more security tools toward consistently controlling assets, identities and data.

As AI and automation continue to help attackers move faster, the ability to detect and respond quickly will increasingly determine the real scale of business impact.

References

Government of Vietnam – Decree No. 327/2026/ND-CP

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page