A law built for content, not extortion
Vietnam's Law on Cybersecurity No. 116/2025/QH15 took effect on July 1, 2026, replacing the 2018 Cybersecurity Law and the 2015 Law on Cyber Information Security with a single, 8-chapter, 58-article framework (full text, Government Portal). Passed by the National Assembly on December 10, 2025, it hands the Ministry of Public Security (MPS) some of the most aggressive content and data powers in Southeast Asia: service providers must remove content the ministry deems illegal within 24 hours, or six hours in cases touching national security, and must hand over user data within 24 hours — three in emergencies (Rajah & Tann Asia; Government Portal summary). The law also formalizes "data security" as a standalone legal concept, requiring encryption and risk assessments for cross-border transfers, and gives MPS "prime responsibility" for combating cyberattacks nationwide.
What the law does not contain is any dedicated ransomware regime. There is no requirement to report a ransomware incident specifically (as opposed to a generic "cybersecurity incident"), no ransom-payment disclosure obligation, and no guidance on whether or how a Vietnamese company can lawfully pay an extortion demand. Critical-infrastructure operators face annual self-inspection filings due before October each year, and information-system managers must "promptly report" detected violations to MPS's cybersecurity force — but nothing in the statute distinguishes a ransomware crypto-locking event, which typically demands a response measured in hours, from routine incident logging measured in days.
The Hansoll test case
That gap became concrete on June 8, 2026, when the ransomware group Payload listed Hansoll Textile — a Vietnam-based knitwear manufacturer supplying US, European, and Japanese apparel brands — on its extortion leak site, claiming compromised employee and third-party credentials and broader infostealer activity across the company's external attack surface (ransomware.live victim record). Hansoll is not an isolated case: manufacturing accounts for roughly 30% of ransomware attacks recorded against Vietnamese organizations, more than any other sector, per CYFIRMA's threat-landscape tracking (CYFIRMA Vietnam report).
Under Law 116, Hansoll's disclosure obligations run through the same generic incident-reporting channel as a phishing complaint or a leaked customer database — there is no MPS unit, timeline, or public dashboard specific to extortion events, and no legal clarity on whether paying Payload to prevent a data leak would itself trigger scrutiny. Compare that with Switzerland, where Stadler Rail this week publicly refused a $12.3 million ransom from the Everest group and filed a criminal complaint — a decision made under a regime, however imperfect, where ransom payment carries clear legal and reputational stakes that companies can weigh (The Record). Vietnamese firms facing the same choice have no equivalent signal from their own regulator.
Steelmanning the MPS approach
There's a real case for what Vietnam built. Ransomware rarely announces itself as ransomware in its first hour — early alerts look like generic intrusions, and a narrow rule mandating disclosure only for confirmed encryption events would let attackers exploit the ambiguity window to argue a report wasn't yet due. A single, broad incident-reporting duty, paired with MPS's own "prime responsibility" for coordinating national response, is simpler for under-resourced SMEs (Hansoll-sized firms rarely have dedicated incident-response counsel) to comply with than a matrix of attack-specific rules like the EU's NIS2 or the emerging patchwork of US state ransom-payment disclosure laws. Vietnam is also managing a genuine regional extortion crisis on multiple fronts: this week's US State Department visa restrictions on individuals "responsible for, or complicit in" Southeast Asian cyberscam networks, announced by Secretary Rubio during ASEAN meetings in Manila on July 23, 2026, underscore how much of the region's cybercrime problem is scam-and-trafficking-adjacent rather than pure ransomware, and a content-and-data-first law reflects those priorities (The Record).
Why the gap still matters
That case doesn't survive contact with what ransomware actually requires: speed and specificity. A generic reporting duty tells a victim what to disclose about state-security-adjacent content violations in granular, hours-denominated detail, while leaving the decision that matters most to a ransomware victim — negotiate, pay, or refuse — entirely unaddressed. Firms get maximal certainty about what MPS can compel from them and minimal certainty about what MPS expects of them when criminals, not the state, come calling. The asymmetry is telling: Vietnam wrote precise deadlines for content takedowns that protect state interests, and vague ones for the extortion attacks that hit its own manufacturing base hardest.
A proportionate fix doesn't require Vietnam to import a full EU-style critical-entity regime overnight. It requires MPS to issue implementing guidance — decrees are still pending on several parts of Law 116 — that sets a ransomware-specific reporting clock (even a generous 72 hours, matching common international practice) and states plainly whether ransom payment is lawful, discouraged, or conditioned on reporting. Absent that, Hansoll and the next manufacturing-sector victim are left navigating a 24-hour-takedown regime built for speech, applied by analogy to a crime it was never designed to answer.