
Cybercrime becoming increasingly "professional"
In August 2025, authorities in Dak Lak dismantled a fraud ring operating through a cryptocurrency project, which misappropriated approximately VND1,275 billion from thousands of victims across multiple provinces and cities.
Disguised behind trendy concepts such as blockchain, AI, and sophisticated investment platforms, the fraudsters constructed an ostensibly trustworthy "ecosystem" promising lucrative returns to entice investors. Ultimately, numerous individuals lost everything.
Shortly before that incident, 343 individuals in Dong Nai were indicted in a case involving the misuse of computer networks and telecommunications to appropriate property. Many originally sought employment, only to be drawn into an organized assembly line with clearly defined roles: finding victims, building trust, and closing transactions. The entire operation functioned like an enterprise, except the "products" which sold deceptive scams.
In April of the same year, the Ministry of Public Security (MPS) dismantled a transnational high-tech fraud ring involving 55 suspects. Within approximately 20 days, the group placed thousands of calls posing as authorities, bank officials, or family members to steal funds from numerous victims.
Three cases across three regions using three distinct methods reveal a clear trend: cybercriminals in Vietnam have fundamentally shifted their approach. They no longer operate as fragmented scam groups, but function with high professionalism, structured organization, and the capability to scale rapidly.
When crime functions as an "industry"
MPS indicates that sophisticated scams are no longer isolated incidents.
Between 2020 and 2025, Vietnam recorded over 24,000 online fraud cases resulting in total damages approaching VND40 trillion, averaging more than 13 cases per day. In the first 11 months of 2025 alone, stolen assets reached approximately VND6 trillion.
However, financial losses represent only the tip of the iceberg. According to the National Cyber Security Association, information systems in Vietnam weathered roughly 552,000 cyberattacks in 2025 alone.
These figures demonstrate that criminals no longer target isolated individuals; they have expanded their focus across the digital space where data, accounts, and economic cash flows move daily.
What sets these recent cases apart is their operational structure. Criminals recruit staff, assign tasks, extract data, craft scripts, optimize profits, and expand geographical reach much like a commercial firm. The primary difference is that their "business" trades on human trust rather than goods or services.
Behind this trend lies a simple formula: high profit margins coupled with low operational costs and minimal perceived criminal risk. This environment enables fraud rings to grow increasingly sophisticated, professional, and interconnected across borders.
The primary concern extends beyond financial losses to the erosion of trust in the digital ecosystem. As suspicion surfaces in routine transactions, cyber fraud ceases to be a mere criminal law issue and transforms into a systemic economic risk.
Modernizing defense strategy
As criminal methods evolve, state authorities need to adapt their counter-measures to address rapidly changing threats.
Directive 30, issued on July 30, 2026, represents an updated strategic outlook by the Government. In its implementation framework, Directive 30 officially replaces Directive 21 from 2020 as well as two Prime Ministerial dispatches issued in 2024 and 2025. Within six years, this marks the fourth high-level directive issued on the same issue.
The continuous escalation of directive measures reflects a harsh reality: criminals evolve far faster than traditional management. The directive candidly admits that public awareness campaigns lag behind new tactics, state management retains loopholes, and illicit trading of identity data, bank accounts, and SIM cards persists.
The key shift lies in the State's fundamental perspective:
Earlier strategies focused heavily on investigation and prosecution after financial damage occurred; Directive 30 pivots decisively toward prevention.
The directive acknowledges that AI, big data, cryptocurrencies, bank accounts, electronic identification accounts, and unregistered "junk" SIM cards have fundamentally altered criminal operations.
The primary goal is no longer just mitigating damage after the fact, but closing vulnerabilities to prevent fraudulent activity at the outset.
Implementation strategy has adapted accordingly. Rather than treating fraud strictly as a law enforcement matter, Directive 30 mobilizes stakeholders across the entire governance system, including banking, telecommunications, science and technology, judicial bodies, and local authorities.
Crucially, the directive targets the structural enablers of cybercrime: unregistered SIMs, payment accounts, identity data, e-wallets, mobile money, e-commerce platforms, and illegal financial flows. By severing the key operational nodes supporting fraudulent networks, the strategy aims to dismantle the infrastructure that sustains organized cybercrime.
Lan Anh