// 2 ZERO-DAY · 5 CVE · 3 EXPLOIT IN THE LAST 24H
In Q1 2026, 2.56% of Vietnamese SMEs were hit by ransomware, a slight decline from 2.91% in Q1 2025. The figure, published July 16 by Kaspersky and picked up by local outlets, appears reassuring but conceals a more complex reality: the true frequency of attacks is likely far higher, and the multi-stage nature of modern operators makes traditional statistics inadequate for measuring risk. Vietnamese SMEs remain exposed to a threat measured not only in encrypted systems, but in those that never reach the final stage because they were blocked earlier.

In Q1 2026, 2.56% of Vietnamese SMEs were hit by ransomware, a slight decline from 2.91% in Q1 2025. The figure, published July 16 by Kaspersky and picked up by local outlets, appears reassuring but conceals a more complex reality: the true frequency of attacks is likely far higher, and the multi-stage nature of modern operators makes traditional statistics inadequate for measuring risk. Vietnamese SMEs remain exposed to a threat measured not only in encrypted systems, but in those that never reach the final stage because they were blocked earlier.

Key Takeaways
  • The ransomware rate on Vietnamese SMEs fell from 2.91% to 2.56% year-on-year, while the Southeast Asian average rose from 2.92% to 3.51%.
  • India and Indonesia lead the regional increase: respectively from 3.18% to 4.07% and from 2.83% to 4.01%.
  • The counting methodology excludes attacks blocked in preliminary stages, creating a "dark figure" of unquantified threats.
  • The Gentlemen, an emerging group since July 2025, develops proprietary tools and allies with initial access brokers, lowering the barrier to entry for less sophisticated actors.

The Decline That Deceives: Why 2.56% Is Not Good News

The shift from 2.91% to 2.56% can read as improvement. Kaspersky contextualizes it immediately: the decline is artifactual, not structural. Official statistics count as "hit" only SMEs where ransomware completed the infection, encryption, and extortion cycle. Attacks intercepted during intrusion, reconnaissance, or lateral movement stages are excluded from the count.

This methodological discrepancy creates a significant information gap. A Vietnamese SME that blocks an attack at the reconnaissance phase does not appear in the data; one that gets encrypted does. Year-on-year comparison therefore becomes unreliable as an indicator of actual security posture, especially if preventive defenses improve without a decrease in attempt frequency.

The regional context reinforces this cautious reading. The Southeast Asian average grew from 2.92% to 3.51%, with India and Indonesia accelerating. Singapore and Malaysia show slight upward trends. In this picture, Vietnam appears as a downward outlier rather than a success model.

"The simple implementation of data backup mechanisms will not be sufficient to protect companies, especially because most ransomware groups today use 'double extortion' tactics: they encrypt data and simultaneously threaten to leak sensitive information."
— Fedor Sinitsyn, Kaspersky security expert

Double Extortion and the Obsolescence of Backups

Sinitsyn's quote identifies a tactical shift that transforms the defense model. Offline backups, traditionally considered a sufficient measure, lose effectiveness when extortion splits in two: encryption hits availability, the threat of publication hits confidentiality. The threat actor threatens to make sensitive data public regardless of the victim's ability to restore systems.

This evolution shifts the cost-benefit calculus for victims. Restoration from backup solves the operational problem but not the legal or reputational one of data leakage. For Vietnamese SMEs integrated into regional supply chains, the second component is often more damaging than the first: loss of contracts with international partners exceeds the ransom cost.

SMEs as a Springboard: The Supply-Chain Risk

Adrian Hia, Kaspersky's APAC Managing Director, adds a systemic dimension to individual risk. "SMEs often lack the resources to maintain dedicated cybersecurity teams or comprehensive patch management, making them easy targets." This structural vulnerability does not stay confined: "Hackers often view small and medium enterprises as a springboard to penetrate deeper into the supply chains of large enterprises."

The mechanism is known in supply-chain security literature but gains geographic concreteness here. Vietnam hosts hundreds of SME subcontractors for regional manufacturing, technology, and textile conglomerates. An intrusion in one, even if not carried through to ransomware, can provide a pivot point for subsequent attacks on higher-value targets. The attacker invests minimal resources in an SME to gain privileged access to a richer ecosystem.

Hia does not specify sectors or documented cases, but the logic aligns with Vietnam's industrial structure. The source provides no data on Vietnamese victims actually used as bridges to larger targets, nor confirms this pattern was observed in the Q1 2026 sample.

The Gentlemen and the Democratization of Access

The most active ransomware groups by victim count on Dedicated Leak Sites in Q1 2026 are Clop (14.42%) and Qilin (12.34%). Third place goes to The Gentlemen, which appeared in July 2025 and is rising rapidly. The group stands out for two documented characteristics: it develops proprietary intelligence-gathering tools, indicating internal engineering capability, and allies with Initial Access Brokers for preliminary access acquisition.

The IAB partnership is the salient point. It drastically lowers the barrier to entry for emerging groups: they no longer need to develop initial intrusion capabilities, only encryption, extortion pressure management, and leak infrastructure maintenance. The Gentlemen buys accesses and monetizes them, specializing in the attack's final phase. This division of labor increases the number of potentially active actors in the landscape.

The source does not explicitly link The Gentlemen to Vietnamese victims in Q1 2026. Its inclusion in the Kaspersky report suggests, however, that the group is considered relevant to the regional threat.

What to Do Now

Kaspersky recommends five specific lines of action, quoted verbatim from editorial sources:

  • Software updates: keep systems updated to reduce the exploitable attack surface.
  • Multi-layered defense with lateral movement detection: implement controls capable of identifying lateral movement within the network, not just initial penetration.
  • Independent offline backups: maintain copies disconnected from the production network, with periodic integrity verification.
  • Anti-APT and EDR solutions: deploy tools specific to advanced persistent threat detection and endpoint detection and response.
  • Supply-chain incident response plan: prepare operational procedures to manage incidents involving integrated suppliers or partners.

The recommendation on the supply-chain plan deserves emphasis given the specificity of the Vietnamese context. This is not a generic best practice but an adaptation to an industrial structure where SMEs function as connecting links between broader ecosystems.

The Real Metric to Watch

The 2.56% figure is technically correct but strategically misleading. The relevant indicator is not the percentage of encrypted SMEs, but the frequency of attacks blocked in preliminary stages and the evolution of operator tactics. An increase in intrusions interrupted before encryption would signal more effective defenses; a decrease could simply indicate attackers are pivoting to easier targets, not that the phenomenon has diminished.

Vietnam, with its fabric of subcontractor SMEs and its position in regional supply chains, is a case study of how the wrong metric generates wrong assessments. The percentage decline offers a political window of opportunity for those wanting to declare success, but the technical reading suggests caution: the threat has not attenuated, it has only moved to less visible zones of the kill chain.

For security leaders, the priority action is not to interpret 2.56% as a positive signal, but to ask intelligence providers and technology partners for data on preliminary attack stages. The dark figure of reconnaissance and lateral movement is the true thermometer of risk.

Information has been verified against cited sources and updated at time of publication.

Sources


Sources and references
  1. vietnam.vn
  2. mmosite.vn