On the morning of April 1, after more than a week of ransomware attacks, VNDIRECT's money trading system, underlying securities trading and derivatives trading systems were reopened, based on restoring connections with the Hanoi Stock Exchange - HNX and Ho Chi Minh City Stock Exchange - HoSE.

Thus, after 1 week of fixing the ransomware attack on the system, VNDIRECT has been licensed by the Vietnam Stock Exchange to reopen the trading system. The two stock exchanges HNX and HoSE have also reopened trading connections with VNDIRECT.

In the information shared on April 1, VNDIRECT said that on the first day of reopening trading, customers can access their accounts, perform basic transactions, warrant transactions, and derivative transactions, through the DStock and VNDIRECT applications.

Informing that the unit is still reviewing and upgrading to reopen all products and services, VNDIRECT also admitted that: The time to reopen transactions and gradually restore features on the system will inevitably have some minor technical errors. VNDIRECT has strengthened customer support and information channels to ensure that users' questions and requests are resolved promptly and completely.

W-su-co-tan-cong-ransomware-vndirect-1-1-1.jpg
VNDIRECT system's trading activities have been reopened since April 1, one week after the ransomware attack was detected. Photo: DL

According to the roadmap to reopen systems and products, utilities that VNDIRECT announced to customers on March 27, in the coming days, this securities company will continue to implement the last two phases of the roadmap, specifically putting other financial products back into operation and restoring all system features.

Speaking to VietNamNet reporter, expert Vu Ngoc Son, Technical Director of Vietnam National Cyber ​​Security Technology Joint Stock Company - NCS commented: VNDIRECT's ability to reopen trading activities after 8 days of experiencing a ransomware attack is a remarkable effort.

“With an incident like VNDIRECT’s, 8 days can be considered a quick fix. Because, in addition to having to restore data, the operations team also rebuilt the entire system, checked and assessed security, and worked with related parties such as HNX or HoSE to reconnect. These things all take a lot of time, VNDIRECT probably had to do many things at the same time to be able to quickly bring the service back!” , Mr. Vu Ngoc Son expressed his opinion.

Referring to the situation on the morning of April 1, some users had difficulty accessing the system, or some customers were able to access the system but could not make other transactions, expert Vu Ngoc Son analyzed: As soon as the system was reopened, the number of users accessing it would be extremely large, this is also an understandable psychology because investors have waited a week to be able to return to trading.

“Users accessing the service when it is back online will cause local overload. However, after a few hours, the local congestion will be resolved. I think the VNDIRECT system will operate more stably this afternoon,” said Mr. Vu Ngoc Son.

A security expert with many years of experience in the industry said that the fact that the Vietnam Stock Exchange allowed VNDIRECT to reopen its trading system and the two exchanges HNX and HoSE restored trading connections to the VNDIRECT system partly shows that the cyber attack on this securities company has been resolved and the security of the system has been ensured.

Informing the press on March 29, VNDIRECT said that as soon as the incident was detected, functional units of the National Cyber ​​Security Center under Department A05 (Ministry of Public Security); VNCERT/CC, NCSC centers under the Department of Information Security (Ministry of Information and Communications) and many experts from large cyber security companies in Vietnam accompanied and supported the operation team to promptly handle the incident, review and restore the system.

On the same day, March 29, a representative of the Department of Information Security (Ministry of Information and Communications) affirmed: During the recovery process, the units coordinated very carefully, closely following the progress to ensure the system operates safely and stably when it returns, while strengthening information security for the system to avoid similar incidents that may occur. It is known that by noon on March 31, the functional units had completed the assessment of the safety and network security of the VNDIRECT system.

According to experts, the incident that VNDIRECT encountered this time not only provided a lesson for the securities company that encountered the incident but also a common lesson for many agencies and organizations in Vietnam. Agencies, organizations and businesses all need to be aware that when transforming digitally and participating in the digital environment, ensuring information security for systems, especially systems that store and process customer data, is extremely important.

Obviously, it is time for awareness of cybersecurity and safety of organizations and businesses in Vietnam to be raised, only then can we protect the achievements of digital transformation and protect Vietnam's prosperity in cyberspace.

In a sharing at the workshop "Timely identification of potential security threats within critical information systems" held in 2023, a representative of HPE Vietnam said that, according to statistics, each ransomware attack causes an average of about 1.85 million USD in damage for businesses to recover. However, physical damage is just the tip of the iceberg, the hidden part causes businesses to lose more than the disruption of operations due to cyber attacks; on average, a business that is attacked by a cyber attack will have up to 21 days of disruption and business stoppage.
The Department of Information Security warns that data encryption attacks are on the rise . Recognizing that data encryption attacks - ransomware - are on the rise, the Department of Information Security has just requested agencies, organizations and businesses nationwide to review and deploy measures to ensure the safety of information systems.