An employee continuously receives login verification notifications, even at midnight. A person claiming to be the IT department sends a message that just accepting a notification will stop everything. They follow suit, and the attacker immediately gets access to the internal network without exploiting any technical vulnerabilities. This is almost exactly how Uber was attacked in September 2022[2], causing the company's internal system to be compromised in just one night. Many serious threats do not come from internal vulnerabilities, but form outside the defensive perimeter: an advertised account, a fake website, a publicly posted piece of internal code - a layer of risk that firewalls or antivirus software can hardly cover.
Shifting thinking from passive to active
The issue is even more urgent as the attack speed has changed under the impact of AI. According to Mr. Tran Minh Quang, Director of the Center for Analysis and Sharing Network Security Risks, Viettel Cyber Security, previously, from when a vulnerability was announced with a patch to when bad actors created an exploit tool, it could take several weeks or months. But "currently, with the support of AI, this time can be shortened to just a few hours or days", making the monthly or quarterly patch model no longer suitable.

According to IBM's Cost of a Data Breach Report 2026, on average an organization takes 247 days to detect and handle a data leak - more than eight months for an attacker to be present without being detected. For every four targeted attacks, one involves AI, an increase of 56% compared to the previous year, causing the cost of each case to increase by about one million USD[3].
Instead of waiting for an alarm when it has been breached, early warning solutions proactively collect leaked data from thousands of global sources to detect and warn of threats from when they are a threat. This approach is called threat intelligence. In the first half of 2026 alone, Viettel Threat Intelligence recorded 302 data leaks in Vietnam, an increase of 58.1% over the same period, with more than 978.7 million records and nearly 6.8 TB of data. Along with that, more than 16.5 million records of personal accounts were stolen, mainly through malware that steals information[2]. This advantage comes from the network of Network Security Operation Centers in 15 countries and information sharing with FIRST, APWG.
Solving two common practical problems in businesses
Two common risks for Vietnamese businesses are fake websites and internal account leaks. With fake websites, according to Mr. Quang, the difficulty lies in the processing stage, most of these pages are registered abroad, using anonymous services and constantly changing infrastructure, causing removal to take many days, even weeks.
To shorten this time, Viettel Threat Intelligence maintains a direct channel with domain name registrants, hosting providers and international anti-fraud organizations, thereby quickly processing according to each country's mechanism. In the fields of banking, finance and e-commerce, reducing processing time from a few days to a few hours helps minimize financial and reputational losses.
With the leakage of internal accounts, the consequences are much more serious. A large commercial bank in Vietnam once encountered common risks throughout the industry, login information was advertised for sale on an underground forum, some old systems were slow to update patches, personnel or outsourced partners leaked authentication information to the public source code warehouse.
After 12 months of monitoring, Viettel Threat Intelligence early detected hundreds of compromised accounts, prevented 15 customer data sales in the fourth quarter of 2025 and helped the bank reduce 40% of incident handling time[5]. Viettel Cyber Security estimates the avoided damage value for this bank is about 50 billion VND per year. Meanwhile, the global average cost for each data leak recorded by IBM in July 2026 is 4.99 million USD[6], the highest level since the report was released, meaning that just preventing a few serious incidents is enough to compensate for the monitoring investment.

Early warnings are only valuable when businesses have time to act.
According to IBM, the organization applying deep AI and automation to network security monitoring handles incidents faster than an average of 65 days and saves about 1.93 million USD per incident.
However, early warnings cannot replace the protective layers inside the business. A leaked account warning is difficult to take effect if the business cannot quickly lock the account, change the password, check the access history or revoke the granted rights. Businesses therefore still have to maintain basic measures: multi-factor authentication, strict access decentralization and clear incident response procedures.
When the attack speed has far exceeded the periodic patch cycle, the question for businesses is no longer whether to invest in early warning or not, but whether the internal response process and capacity are fast enough to turn warnings into actions, before external risks become internal incidents.
---------------------------
[1] Report on Information Security Risks in Vietnam in the first 6 months of 2026
[2] The actual case at Uber, September 2022, Reuters, Bleeping Computer and The New York Times
[3] IBM, Cost of a Data Breach Report 2026 (published in July 2026).
[4] Report on Information Security Risks in Vietnam in the first 6 months of 2026
[5] Viettel Cyber Security, viettelsecurity. com
[6] IBM, Cost of a Data Breach Report 2026 (announced in July 2026)
