Vietnam ransomware and cyber extortion policy

Vietnam's New Cybersecurity Law Gives Police Sweeping Powers But No Ransomware Playbook

Law No. 116/2025/QH15 took effect July 1 with 24-hour takedown powers for police but no ransom-reporting or payment-disclosure regime, weeks after Payload hit textile maker Hansoll.

Vietnam's Cybersecurity Law: Precision vs. Silence People of Internet Research · Vietnam 24 hrs Content takedown deadline MPS-mandated removal window for fl… 24 hrs User data disclosure window Companies must hand MPS user data … ~30% Manufacturing share of attacks Share of Vietnam ransomware incide… None Ransomware-specific reporting rule Law 116 has no dedicated ransomwar… peopleofinternet.com
Vietnam's Cybersecurity Law: Precision… People of Internet Research · Vietnam 24 hrs Content takedown deadline 24 hrs User data disclosure window ~30% Manufacturing share of attacks None Ransomware-specif ic reporting rule peopleofinternet.com

Key Takeaways

A law built for content, not extortion

Vietnam's Law on Cybersecurity No. 116/2025/QH15 took effect on July 1, 2026, replacing the 2018 Cybersecurity Law and the 2015 Law on Cyber Information Security with a single, 8-chapter, 58-article framework (full text, Government Portal). Passed by the National Assembly on December 10, 2025, it hands the Ministry of Public Security (MPS) some of the most aggressive content and data powers in Southeast Asia: service providers must remove content the ministry deems illegal within 24 hours, or six hours in cases touching national security, and must hand over user data within 24 hours — three in emergencies (Rajah & Tann Asia; Government Portal summary). The law also formalizes "data security" as a standalone legal concept, requiring encryption and risk assessments for cross-border transfers, and gives MPS "prime responsibility" for combating cyberattacks nationwide.

What the law does not contain is any dedicated ransomware regime. There is no requirement to report a ransomware incident specifically (as opposed to a generic "cybersecurity incident"), no ransom-payment disclosure obligation, and no guidance on whether or how a Vietnamese company can lawfully pay an extortion demand. Critical-infrastructure operators face annual self-inspection filings due before October each year, and information-system managers must "promptly report" detected violations to MPS's cybersecurity force — but nothing in the statute distinguishes a ransomware crypto-locking event, which typically demands a response measured in hours, from routine incident logging measured in days.

The Hansoll test case

That gap became concrete on June 8, 2026, when the ransomware group Payload listed Hansoll Textile — a Vietnam-based knitwear manufacturer supplying US, European, and Japanese apparel brands — on its extortion leak site, claiming compromised employee and third-party credentials and broader infostealer activity across the company's external attack surface (ransomware.live victim record). Hansoll is not an isolated case: manufacturing accounts for roughly 30% of ransomware attacks recorded against Vietnamese organizations, more than any other sector, per CYFIRMA's threat-landscape tracking (CYFIRMA Vietnam report).

Under Law 116, Hansoll's disclosure obligations run through the same generic incident-reporting channel as a phishing complaint or a leaked customer database — there is no MPS unit, timeline, or public dashboard specific to extortion events, and no legal clarity on whether paying Payload to prevent a data leak would itself trigger scrutiny. Compare that with Switzerland, where Stadler Rail this week publicly refused a $12.3 million ransom from the Everest group and filed a criminal complaint — a decision made under a regime, however imperfect, where ransom payment carries clear legal and reputational stakes that companies can weigh (The Record). Vietnamese firms facing the same choice have no equivalent signal from their own regulator.

Steelmanning the MPS approach

There's a real case for what Vietnam built. Ransomware rarely announces itself as ransomware in its first hour — early alerts look like generic intrusions, and a narrow rule mandating disclosure only for confirmed encryption events would let attackers exploit the ambiguity window to argue a report wasn't yet due. A single, broad incident-reporting duty, paired with MPS's own "prime responsibility" for coordinating national response, is simpler for under-resourced SMEs (Hansoll-sized firms rarely have dedicated incident-response counsel) to comply with than a matrix of attack-specific rules like the EU's NIS2 or the emerging patchwork of US state ransom-payment disclosure laws. Vietnam is also managing a genuine regional extortion crisis on multiple fronts: this week's US State Department visa restrictions on individuals "responsible for, or complicit in" Southeast Asian cyberscam networks, announced by Secretary Rubio during ASEAN meetings in Manila on July 23, 2026, underscore how much of the region's cybercrime problem is scam-and-trafficking-adjacent rather than pure ransomware, and a content-and-data-first law reflects those priorities (The Record).

Why the gap still matters

That case doesn't survive contact with what ransomware actually requires: speed and specificity. A generic reporting duty tells a victim what to disclose about state-security-adjacent content violations in granular, hours-denominated detail, while leaving the decision that matters most to a ransomware victim — negotiate, pay, or refuse — entirely unaddressed. Firms get maximal certainty about what MPS can compel from them and minimal certainty about what MPS expects of them when criminals, not the state, come calling. The asymmetry is telling: Vietnam wrote precise deadlines for content takedowns that protect state interests, and vague ones for the extortion attacks that hit its own manufacturing base hardest.

A proportionate fix doesn't require Vietnam to import a full EU-style critical-entity regime overnight. It requires MPS to issue implementing guidance — decrees are still pending on several parts of Law 116 — that sets a ransomware-specific reporting clock (even a generous 72 hours, matching common international practice) and states plainly whether ransom payment is lawful, discouraged, or conditioned on reporting. Absent that, Hansoll and the next manufacturing-sector victim are left navigating a 24-hour-takedown regime built for speech, applied by analogy to a crime it was never designed to answer.

Sources & Citations

  1. Law on Cybersecurity No. 116/2025/QH15 (full text)
  2. Vietnam Government Portal — what's new in Law 116/2025/QH15
  3. Rajah & Tann Asia — Law on Cybersecurity analysis
  4. Ransomware.live — Hansoll Textile / Payload victim record
  5. CYFIRMA — Vietnam Executive Threat Landscape Report
  6. The Record — Stadler Rail refuses Everest ransom demand
  7. The Record — State Department visa restrictions on cyber scammers