Vietnam probes suspected cyberattack on national credit database
There has been a suspected data breach at the Vietnam National Credit Information Center (CIC), according to a press release issued by a police agency on Thursday.
The volume of data illegally obtained is being determined, said the Vietnam Computer Emergency Response Team, a cybersecurity department known as A05 and is under Vietnam’s Ministry of Public Security.
The agency urged all organizations and individuals not to download, distribute, exploit, or make use of the leaked data.
In a separate letter sent on the same day to the heads of financial institutions in Vietnam, CIC – a body under the State Bank of Vietnam – acknowledged that the credit information database system may have been attacked by hackers named ShinyHunters. The group posted the data for sale on an international forum on September 9.
“Currently, the incident has not caused any damage or loss. The CIC’s credit information service system is still operating normally,” CIC noted.
Its official website could not be accessed at the time of writing.
The financial body serves as Vietnam’s national credit registry, responsible for collecting, processing, storing, and analyzing the credit information of individuals and institutions in Vietnam.
A report from DataBreaches.Net on September 8 revealed that the hacker provided a large data sample and demanded US$175,000 for the full database.
ShinyHunters described the data as “full country” with more than 160 million records containing “very sensitive information.”
These include general personally identifiable information, credit payment data, risk analysis, credit card details, tax identification numbers, income statements, and outstanding debts.
The hacker’s original post on the cybercrime forum called “Breachstars” is no longer available.
CIC noted that its task force on cybersecurity incident response is working with A05 and partners, such as the state-owned Vietnam Posts and Telecommunications Group and the military-run telecommunications corporation Viettel Group, to inspect and implement enhanced security measures.
They are also investigating the root cause of the potential data breach to take corrective actions.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.








