top of page

When expensive security systems are helpless against hackers: Lessons from the incident at two ministry-level agencies

Information security remains a challenging puzzle for any organization, particularly government regulatory bodies. As cyberattacks grow increasingly sophisticated, investing solely in technology is no longer enough. The recent severe data breach at two ministry-level agencies serves as a clear testament: no matter how advanced a system is, it becomes futile without human operation.

Large-scale data breach at two ministry-level agencies

At the Vietnam Security Summit 2026 held on May 22, Major Tran Trung Hieu - Deputy Director of the National Cyber Security Center and Director of VNCERT (under the Department of Cybersecurity and High-Tech Crime Prevention, Ministry of Public Security, shared information regarding a concerning incident. Accordingly, VNCERT is currently focusing on remediating and handling an exceptionally serious data breach that occurred within the systems of two ministry-level agencies.

Major Tran Trung Hieu, Deputy Director of the National Cyber Security Center, shares at the Vietnam Security Summit 2026 that VNCERT has handled the data breach incident affecting two ministry-level systems.
Major Tran Trung Hieu, Deputy Director of the National Cyber Security Center, shares at the Vietnam Security Summit 2026 that VNCERT has handled the data breach incident affecting two ministry-level systems

In this incident, hackers infiltrated systems and compromised user information, impacting millions of records. Notably, preliminary investigation results as of May 21 revealed that although the affected entities were equipped with a Security Operations Center (SOC) system, it remained completely silent and failed to trigger any alerts regarding the attack. Authorities suspect that the hackers' activities were cleverly masked within normal user traffic, and VNCERT will soon issue an official conclusion.

Owning expensive technology but lacking an operations team

Highlighting this vulnerability, the representative from the National Cyber Security Center emphasized the urgent need to establish dedicated personnel teams. The reality at the recently attacked agencies demonstrates that organizations can spend massive amounts on large-scale monitoring systems like SOCs, yet leave the human element completely unaddressed. A shortage of cybersecurity talent will neutralize any information security efforts made by technical hardware and software.

Looking at the broader picture over the past three years, many entities in Vietnam have fallen victim to major attack campaigns despite procuring highly expensive security systems. The direct cause of this inefficiency is the lack of daily operational staff, let alone the ability to attract high-level technology experts for deep analysis.

Currently, the domestic cybersecurity workforce faces a major challenge, being both insufficient in numbers and lacking in advanced skills. This situation is widespread across enterprises, large conglomerates, and state agencies alike.

To illustrate this, a representative from the Department of Cybersecurity and High-Tech Crime Prevention (A05) previously shared real-world case studies:

  • In one instance, hackers quietly persisted and hid inside an enterprise's system for 9 months before officially launching the attack.

  • During an Incident Response engagement at a major bank, authorities discovered that despite possessing a modern SOC system, a lack of personnel meant monitoring was only maintained for 8 hours during standard business hours. At night, the system was left completely unattended, giving hackers a free pass to operate. This underscores how much system security controls are enhanced when a business implements a 24/7 SOC.

Incident concealment trends and the legal liability of leadership

Another major barrier in information security assurance today is management awareness. Many leaders of critical entities and enterprises are entirely unaware of the cybersecurity incidents unfolding within their own organizations.

Major Tran Trung Hieu shared that he has directly contacted chairpersons and executives of conglomerates to notify them that their systems were compromised. However, the response was often astonishment because their subordinates had not reported it. Only when leadership called to press the IT department did staff admit to it, making excuses that "it has already been handled." The fear of accountability leads subordinates to intentionally conceal incidents rather than reporting them upstream.

These agencies and enterprises all store massive volumes of critical data. Therefore, once an incident occurs, the consequences extend far beyond internal scope, threatening national security and the rights of millions of citizens.

Given that many leaders have yet to pay sufficient attention - resulting in a wave of personal data leaks, document exposure, and state secrets breaches - authorities have issued stern warnings. In addition to continuous written reminders, the VNCERT representative asserted that if information security incidents cause severe consequences to national security or leak confidential documents, regulatory bodies may consider criminal prosecution against the head of the organization for "Irresponsibility causing serious consequences" and "Deliberate violation of regulations."

Ultimately, technology is merely a supporting tool; people are the deciding factor. The incident at the two ministry-level agencies is a heavy reminder to all organizations to balance technical infrastructure investment with workforce development. At the same time, proper awareness and serious accountability from leadership stand as the first and most crucial shield protecting the flow of national data.

References: Hackers launched serious data theft attacks against two ministry-level agencies - Vietnamnet

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page