Methodology note: this article relies on a single source, the Vietnamese government portal vietnam.vn, which reports data attributed to a Kaspersky Q1 2026 report without providing access to the primary document. Quotes from Kaspersky experts are reproduced as translated by the source, with no independent verification possible. The portal is not a cybersecurity specialist outlet.
In Q1 2026, 2.56% of Vietnamese small and medium-sized enterprises were hit by ransomware, down from 2.91% in the same period of 2025. The apparent decline masks a tactical evolution that makes the threat harder to detect: according to the sole available source, criminal groups have shifted their activity to the preliminary stages of intrusion and reconnaissance, which do not show up in statistics on completed attacks.
- 3.51% of Southeast Asian SMEs were hit by ransomware in Q1 2026, up from 2.92% in 2025, with India and Indonesia posting the largest increases
- In Vietnam the figure fell from 2.91% to 2.56%, but the source attributes the drop to a threat that has moved into early stages not counted as completed attacks
- Clop and Qilin top the Dedicated Leak Site rankings with 14.42% and 12.34% of victims respectively, followed by the emerging group The Gentlemen
- Vietnamese SMEs are prime targets for double extortion and serve as springboards into large-enterprise supply chains, lacking dedicated security teams and structured patch management
The Misleading Figure: Why Vietnam's Decline Does Not Mean Lower Risk
The contrast between national trends is stark. India rose from 3.18% to 4.07% and Indonesia from 2.83% to 4.01%, both surpassing the regional average of 3.51%. Vietnam, by contrast, shows a retreat. According to the cited source, however, this dynamic reflects a change in how attacks are measured rather than an actual reduction in threat. Attacks blocked in the early stages — initial compromise, lateral movement, intelligence gathering — do not enter the statistical count of completed ransomware incidents.
The mechanism has concrete operational consequences. Vietnamese SMEs, often lacking dedicated IT teams, detect fewer partial intrusions compared to more mature organizations. The visibility gap creates a minefield: the numerical decline discourages security investment precisely when criminal groups are perfecting persistence in target networks.
The Group Landscape: Clop, Qilin, and the Rise of The Gentlemen
The distribution of victims on Dedicated Leak Sites paints a concentrated ecosystem. Clop ranks first with 14.42% of the total, Qilin second with 12.34%. Third place goes to The Gentlemen, a group that emerged in July 2025 and has developed proprietary reconnaissance tools and forged partnerships with Initial Access Brokers. The source does not specify The Gentlemen's direct activity in Vietnam, but places the group in the active operational landscape across the ASEAN region.
The partnership model with Initial Access Brokers describes a modular criminal ecosystem. A group like The Gentlemen can purchase already-compromised access and focus resources on the extortion phase. The source documents this market structure without drawing conclusions about the risk profile for SMEs.
Double Extortion Makes Backups an Illusion of Protection
"The mere implementation of data backup mechanisms will not be sufficient to protect companies, especially because most ransomware groups today use 'double extortion' tactics: they encrypt data and simultaneously threaten to leak sensitive information" Fedor Sinitsyn, Kaspersky security expert, as reported by the source
The quote, as translated by the source, defines the limit of a defensive strategy still widespread among SMEs. Traditional backup assumes the stake is data availability; double extortion shifts the stake to confidentiality. Even with functioning restore systems, the company must negotiate over the non-disclosure of information that could involve customers, suppliers, or intellectual property.
The source does not specify the exact nature of data exfiltrated in the observed campaigns. The dossier does not document particularly targeted sectors or provide details on ransom amounts or negotiation timelines. These limits make it impossible to quantify the direct economic impact on Vietnamese SMEs, even as the risk structure is evident.
Structural Asymmetry: SMEs Without Defenses, Supply Chains Without Shields
Adrian Hia, Kaspersky's Managing Director for Asia Pacific, is cited by the source with a blunt diagnosis: "SMEs often lack the resources to maintain dedicated cybersecurity teams or comprehensive patch management, making them easy targets." The shortfall is not just an individual vulnerability. According to the same source, SMEs are used as springboards into the supply chains of large enterprises.
The mechanism is linear: a third-tier supplier with access to a primary industrial network becomes the path of least resistance to reach higher-value targets. The Vietnamese SME, lacking an internal SOC and often lacking binding security requirements from larger clients, turns its weakness into systemic contagion. The source does not specify whether Vietnamese regulatory frameworks impose security standards on SME suppliers, nor does it document public support initiatives.
What to Do Now
The available source does not list structured operational recommendations from Kaspersky. From the data and quotes reported, however, implications emerge that Vietnamese SMEs and their business partners can consider in their own risk assessments.
Sinitsyn's observation on backups — as reported by the source — suggests that verification of one's recovery strategy must include the exfiltration scenario, not just encryption. The lack of dedicated teams, highlighted by Hia, indicates that SMEs must evaluate forms of external support or resource sharing for patch management and monitoring of early-stage intrusions.
The role of springboard into supply chains finally demands reflection from large-enterprise clients: the security of their own perimeter depends on visibility into smaller-scale suppliers, which the source describes as the weakest and least controlled.
A Decline That Offers No Comfort
The 2.56% figure for Q1 2026, read in isolation, might appear as a positive signal. The source frames it instead as a statistical artifact: the threat has moved where the counters do not reach. For Vietnamese SMEs, the consequence is a double penalty — reduced detection capability and reduced incentive to invest — in a criminal market that, with Clop, Qilin, and The Gentlemen, has demonstrated a preference for precisely this victim profile.
The source offers no projections for subsequent quarters nor indicates whether Kaspersky has recommended specific interventions to Vietnamese authorities. The figure remains, for now, a snapshot to interpret with caution: not for what it shows, but for what it hides.
Information is based on the cited source and current as of publication.
Sources
- https://www.vietnam.vn/it/ma-doc-tong-tien-bua-vay-doanh-nghiep-vua-va-nho-viet-nam
- https://www.vietnam.vn/id/ma-doc-tong-tien-bua-vay-doanh-nghiep-vua-va-nho-viet-nam
- https://vjs.vietnam.vn/assets/images/logo-vietnam.png
- https://www.vietnam.vn/it/
- https://www.vietnam.vn/it/topics
- https://www.vietnam.vn/it/news
- https://www.vietnam.vn/it/political-activities