Illegal Sale of 120 Million Personal Data Records: Key Risks to Watch
On September 24, 2026, Vietnam’s Ministry of Public Security reported that Dak Lak Provincial Police had initiated criminal proceedings in a case involving the alleged illegal collection and sale of approximately 120 million personal data records. The data spans multiple sectors and includes names, dates of birth, citizen identification numbers, addresses, phone numbers, job titles and occupations. No specific CVE has been associated with the case.
The risk associated with personal data increases significantly when separate pieces of information can be combined. A name linked to a phone number, citizen identification number, address and occupation can create a detailed profile that may support impersonation, fraud or social engineering.
The case uncovered in Dak Lak also demonstrates why personal data protection extends beyond passwords or defenses against external hackers. For individuals, the concern is how exposed information could be exploited. For organizations, critical questions include where sensitive data is stored, who can access it, and whether abnormal copying or extraction of large volumes of information can be detected.

What happened to the illegal sale of 120 million personal data records?
On September 24, 2026, the Investigation Police Agency of Dak Lak Provincial Police announced criminal proceedings against Nguyen Hung Trung Phuong and Nguyen Hung Nam Phuong for alleged offenses involving the unlawful provision or use of computer and telecommunications network information, as well as gambling.
According to information published by Vietnam’s Ministry of Public Security, investigators seized two mobile phones and a desktop computer. Examination of these devices identified approximately 120 million personal data records related to multiple provinces, cities, government bodies and businesses across Vietnam.
The data covered several sectors and categories, including:
Credit and banking
Telecommunications
Healthcare
Government officials and public employees
Household businesses
Enterprises
The information identified by authorities included full names, dates of birth, citizen identification numbers, addresses, phone numbers, job titles and occupations.
Preliminary investigation findings indicate that the data had been unlawfully collected in cyberspace before being analyzed, aggregated and sold according to customer requests for financial gain. The suspects allegedly used anonymous Telegram and Facebook accounts, USDT cryptocurrency, bank accounts not registered under their own names, and automatic message deletion to conceal their activities.
Authorities are continuing their investigation. There is therefore no basis at this stage to conclude that all 120 million records originated from a single organization, database or cybersecurity breach.
Why could the collected data create significant risks?
The figure of 120 million is significant, but the types of information involved are equally important when assessing potential harm. Combining multiple data fields can allow malicious actors to build a considerably more detailed profile of an individual.
Data category | Examples disclosed by authorities | Potential risks |
Identity information | Full name, date of birth, citizen ID number | Impersonation and unauthorized identity verification |
Contact information | Address, phone number | Targeted fraudulent calls and messages |
Employment information | Occupation, job title | More convincing social engineering scenarios |
Sector-specific information | Banking, credit, telecom, healthcare | Context that may increase the credibility of impersonation attempts |
Organizational information | Government agencies, household businesses, enterprises | Identification of employees or potential targets |
A caller who already knows a victim’s name, phone number, address or employer can appear more credible. However, possession of accurate personal information does not prove that the caller represents a legitimate bank, government authority or company.
Organizations face an additional concern involving employee and customer data. Job titles, for example, may help malicious actors identify finance personnel, managers or employees with elevated access privileges, enabling more personalized phishing or impersonation attempts.
To assess these risks effectively, organizations need visibility into the personal data they hold, where it resides and how sensitive each dataset is. IPSIP Vietnam’s analysis of personal data exposure in digital environments provides additional context on how personal information can become exposed and the controls organizations should consider throughout the data lifecycle.
How could illegally traded personal data be exploited?
Possession of personal data does not automatically enable an attacker to compromise an account. However, the information can become an input for subsequent stages of fraud or cyberattacks.
One important risk is social engineering - the manipulation of individuals into revealing information, providing authentication credentials, transferring money or performing actions requested by an attacker.
For example, an attacker who already possesses a person’s name, phone number and employment information could impersonate a bank, government agency, delivery company or even someone within the victim’s organization. The next objective could be obtaining a one-time password, login credentials or authentication code, or convincing the victim to visit a fraudulent website.
For organizations, exposed employee information may also support reconnaissance before an attack. Details about employees, positions and organizational structures can help attackers select targets for spear phishing, a more personalized form of phishing aimed at specific individuals or groups.
It is important, however, to distinguish between potential risks arising from exposed data and attack techniques confirmed in this particular case. Authorities have not stated that all 120 million records were used for phishing, account takeover or a specific cyberattack campaign.
What penalties apply to personal data violations in Vietnam?
Vietnam now has a more specialized legal framework for personal data protection. Law No. 91/2025/QH15 on Personal Data Protection took effect on January 1, 2026, and prohibits the purchase and sale of personal data, except where otherwise provided by law.
Article 8 provides that organizations and individuals violating personal data protection requirements may, depending on the nature, severity and consequences of the violation, face administrative penalties or criminal prosecution. Those causing damage may also be required to provide compensation in accordance with applicable law.
Notably, the law establishes several maximum financial penalty frameworks:
For the purchase and sale of personal data, the maximum administrative fine may reach 10 times the revenue obtained from the violation.
For organizations violating rules governing cross-border transfers of personal data, the maximum fine may reach 5% of the organization’s revenue in the immediately preceding year, subject to the conditions and calculation methods established by law.
For other violations of personal data protection requirements, the maximum fine is VND 3 billion.
These maximum amounts apply to organizations. For an individual committing the same violation, the maximum fine is generally half the amount applicable to an organization.
In addition, Decree No. 330/2026/ND-CP, effective from August 19, 2026, provides more specific administrative penalties in the fields of cybersecurity and personal data protection.
These figures represent maximum penalty frameworks or penalties associated with specific categories of violations. They do not mean that every personal data exposure automatically results in the maximum fine. The applicable penalty depends on the conduct, responsible party, severity, consequences and findings of the competent authorities.
Beyond technical security requirements, organizations therefore need to approach personal data protection as part of governance and compliance. IPSIP Vietnam’s analysis of organizational responsibilities for cybersecurity and personal data protection provides additional context on managing data responsibilities under the evolving regulatory environment.
What should individuals and organizations do to protect personal data?
For individuals, the immediate priority is reducing the likelihood that exposed information can be used to compromise accounts or facilitate fraud. Organizations face a broader challenge: identifying where personal data resides, restricting access and monitoring how information is used or transferred outside controlled environments.
For individuals
Never disclose OTPs, passwords, PINs or authentication codes to another person.
Use different passwords for important accounts and enable multi-factor authentication (MFA) whenever available.
Do not trust a caller simply because they know your citizen ID number, address, employer or other accurate personal details.
Avoid opening unknown links, scanning unverified QR codes or installing applications at another person’s request.
Independently verify requests involving banks or government agencies through their official channels.
Limit public exposure of phone numbers, dates of birth, addresses and identity documents on social media.
Monitor transaction notifications and login alerts for banking, email and other critical accounts.
Preserve evidence and report suspected misuse of personal information to the relevant organization or authorities.
For organizations
Establish a Data Inventory covering the personal data the organization collects, processes and stores.
Identify servers, cloud environments, CRM systems, endpoints and SaaS applications containing sensitive information.
Classify data according to sensitivity and intended purpose.
Apply the Least Privilege principle so employees receive only the access required for their roles.
Enable MFA for accounts with access to important datasets.
Monitor bulk downloads, exports and unusual copying of sensitive information.
Apply appropriate encryption and Data Loss Prevention (DLP) controls.
Collect logs from systems containing sensitive data to support anomaly detection and incident investigations.
Revoke unnecessary access promptly when employees change roles or leave the organization.
Maintain an Incident Response Plan for suspected unauthorized access or data exfiltration.
Train employees on phishing, social engineering and appropriate handling of personal data.
What does IPSIP Vietnam’s cybersecurity perspective highlight?
The discovery of approximately 120 million personal data records illustrates that the value of personal information does not lie solely in individual data fields. The ability to combine multiple pieces of information into detailed profiles can significantly increase the potential for misuse.

For individuals, a caller’s knowledge of accurate personal information should never be treated as proof of identity or legitimacy. For organizations, data protection needs to extend across collection, storage, access control, monitoring, sharing and deletion. As data becomes an increasingly important asset, knowing who is accessing it and for what purpose should be treated as a core element of risk management.
References
Vietnam Cybersecurity Magazine - Warning Over an Illegal Market Trading 120 Million Personal Data Records
Vietnam Ministry of Public Security - Criminal Case Launched Over the Illegal Sale of Approximately 120 Million Personal Data Records
Government of Vietnam - Personal Data Trading Prohibited: Administrative Penalties for Personal Data Protection Violations
Government of Vietnam - Decree No. 330/2026/ND-CP on Administrative Penalties in Cybersecurity
Government of Vietnam - Penalties for Processing Personal Data Collected Without the Data Subject’s Consent












