When expensive security systems are helpless against hackers: Lessons from the incident at two ministry-level agencies
- Thanh Hoang

- May 25
- 3 min read
Information security remains a challenging puzzle for any organization, particularly government regulatory bodies. As cyberattacks grow increasingly sophisticated, investing solely in technology is no longer enough. The recent severe data breach at two ministry-level agencies serves as a clear testament: no matter how advanced a system is, it becomes futile without human operation.
Large-scale data breach at two ministry-level agencies
At the Vietnam Security Summit 2026 held on May 22, Major Tran Trung Hieu - Deputy Director of the National Cyber Security Center and Director of VNCERT (under the Department of Cybersecurity and High-Tech Crime Prevention, Ministry of Public Security, shared information regarding a concerning incident. Accordingly, VNCERT is currently focusing on remediating and handling an exceptionally serious data breach that occurred within the systems of two ministry-level agencies.

In this incident, hackers infiltrated systems and compromised user information, impacting millions of records. Notably, preliminary investigation results as of May 21 revealed that although the affected entities were equipped with a Security Operations Center (SOC) system, it remained completely silent and failed to trigger any alerts regarding the attack. Authorities suspect that the hackers' activities were cleverly masked within normal user traffic, and VNCERT will soon issue an official conclusion.
Owning expensive technology but lacking an operations team
Highlighting this vulnerability, the representative from the National Cyber Security Center emphasized the urgent need to establish dedicated personnel teams. The reality at the recently attacked agencies demonstrates that organizations can spend massive amounts on large-scale monitoring systems like SOCs, yet leave the human element completely unaddressed. A shortage of cybersecurity talent will neutralize any information security efforts made by technical hardware and software.
Looking at the broader picture over the past three years, many entities in Vietnam have fallen victim to major attack campaigns despite procuring highly expensive security systems. The direct cause of this inefficiency is the lack of daily operational staff, let alone the ability to attract high-level technology experts for deep analysis.
Currently, the domestic cybersecurity workforce faces a major challenge, being both insufficient in numbers and lacking in advanced skills. This situation is widespread across enterprises, large conglomerates, and state agencies alike.
To illustrate this, a representative from the Department of Cybersecurity and High-Tech Crime Prevention (A05) previously shared real-world case studies:
In one instance, hackers quietly persisted and hid inside an enterprise's system for 9 months before officially launching the attack.
During an Incident Response engagement at a major bank, authorities discovered that despite possessing a modern SOC system, a lack of personnel meant monitoring was only maintained for 8 hours during standard business hours. At night, the system was left completely unattended, giving hackers a free pass to operate. This underscores how much system security controls are enhanced when a business implements a 24/7 SOC.
Incident concealment trends and the legal liability of leadership
Another major barrier in information security assurance today is management awareness. Many leaders of critical entities and enterprises are entirely unaware of the cybersecurity incidents unfolding within their own organizations.
Major Tran Trung Hieu shared that he has directly contacted chairpersons and executives of conglomerates to notify them that their systems were compromised. However, the response was often astonishment because their subordinates had not reported it. Only when leadership called to press the IT department did staff admit to it, making excuses that "it has already been handled." The fear of accountability leads subordinates to intentionally conceal incidents rather than reporting them upstream.
These agencies and enterprises all store massive volumes of critical data. Therefore, once an incident occurs, the consequences extend far beyond internal scope, threatening national security and the rights of millions of citizens.
Given that many leaders have yet to pay sufficient attention - resulting in a wave of personal data leaks, document exposure, and state secrets breaches - authorities have issued stern warnings. In addition to continuous written reminders, the VNCERT representative asserted that if information security incidents cause severe consequences to national security or leak confidential documents, regulatory bodies may consider criminal prosecution against the head of the organization for "Irresponsibility causing serious consequences" and "Deliberate violation of regulations."
Ultimately, technology is merely a supporting tool; people are the deciding factor. The incident at the two ministry-level agencies is a heavy reminder to all organizations to balance technical infrastructure investment with workforce development. At the same time, proper awareness and serious accountability from leadership stand as the first and most crucial shield protecting the flow of national data.
References: Hackers launched serious data theft attacks against two ministry-level agencies - Vietnamnet











Comments