
Speaking at a conference on the Cybersecurity Law and Personal Data Protection Law on August 21, Senior Lieutenant Colonel Nguyen Dinh Do Thi, of the Department of Cybersecurity and High-Tech Crime Prevention (A05) under the Ministry of Public Security, reported that dozens of students have committed suicide in recent years after facing online defamation and abuse.
Documented cases span multiple localities, involving students from 8th to 11th grade. Some left suicide notes expressing an inability to endure the overwhelming pressure from fabricated information and malicious online comments.
"Virtual actions on digital platforms carry tragic, real-world consequences. A few lines of text or leaked, distorted images have driven young students to end their lives," Thi said.
These incidents underscore that cyberspace is no longer isolated from physical reality. Once leaked, personal information and images can directly damage honor, well-being, and life itself.
Personal data: 'gold mine' for cybercriminals
Thi noted that rapid digital transformation has coincided with complex personal data violations. Exploited data ranges from basic details like full names, dates of birth, and phone numbers to sensitive records, including bank account numbers and biometric data.
On encrypted groups and underground forums, Vietnamese user data files involving tens of millions of records are openly traded. In 2025 alone, A05 and local police uncovered over 30 cases involving the illicit trading and exploitation of approximately 160 million personal data records.
Some cases were particularly large. In November 2022, Phu Tho police, in coordination with A05, arrested a group accused of offering 2.2 million personal data records for sale. In 2025, authorities dismantled a network trading 56 million records.
In 2026, Nghe An police prosecuted an individual for allegedly buying and selling 50 million personal data records, while Lam Dong police prosecuted a 10th-grade student accused of hacking into a system, stealing and selling 20 million records.
"Criminals have come to regard personal data as a new kind of 'gold mine'," he said.
Stolen data has become an input for various forms of cybercrime, particularly online fraud. According to the official, criminal networks can involve hundreds or even thousands of people and develop hundreds of scripts based on current events to approach potential victims.
AI is also being used to accelerate cyberattacks. In the first six months of 2026, VNCERT recorded around two million cybersecurity attack alerts, with about 50 percent of the attacks involving AI. The technology can help automate scanning, malware infection and system intrusion at greater speed.
AI and deepfakes are also being used to manipulate and edit images, create distorted or defamatory content, and impersonate individuals. During the first half of the year, A05 detected tens of thousands of pieces of distorted information and posts circulating in cyberspace.
New law tightens data protection
The Personal Data Protection Law was passed by the National Assembly on June 26, 2025, and took effect on January 1, 2026. The law more clearly defines the rights and obligations of data subjects and the responsibilities of parties involved in processing personal data.
Users have the right to know how their personal data is being processed. They have a right to give or withdraw consent; access, correct, delete or request restrictions on the processing of their data; object to processing; and file complaints, denunciations or lawsuits and seek compensation in accordance with the law.
Notably, consent is valid only when it is given voluntarily and the user is clearly informed about the type of data being processed, the purpose of processing, the data controller and their own rights and obligations.
Individuals, meanwhile, are also required to protect their own data and respect other people's data. The law prohibits unlawful data processing, using another person's data to commit violations, illegally buying or selling personal data, and stealing, intentionally disclosing or losing data.
For organizations and businesses, the law requires the appointment of personnel or a department responsible for personal data protection. When processing or transferring data across borders, relevant parties must comply with prescribed impact assessment requirements.
Penalties have also been designed to serve as a deterrent. The illegal sale of personal data can result in a fine of up to 10 times the proceeds generated from the violation. For organizations violating regulations on cross-border personal data transfers, the maximum fine can reach 5 percent of the previous year's revenue.
However, Thi said data protection is not solely the responsibility of regulators or businesses. Users also need to be careful about what they post online, think carefully before sharing personal information in exchange for a service, and avoid opening unfamiliar files or installing applications from unknown sources.
Du Lam