Vietnamese banks started deleting more than 86 million bank accounts last September.
Of the roughly 200 million accounts on the country’s books, only 113 million personal accounts and some 711,000 organizational ones survived the biometric verification requirements introduced by the State Bank of Vietnam (SBV).
The rest, close to 43% of the total, were dormant, duplicated, unverifiable or opened by someone who never intended to be found.
How does a banking system end up with 86 million accounts nobody can put a face to? Slowly, is the answer. Account opening got easier every year. Checking who still controlled those accounts did not.
Identity records, transaction monitoring, and fraud alerts grew up in different systems at different times, and the connections between them remain scattered. In the end it took a national biometric identity program, run with the Ministry of Public Security, to do the clean-up that the industry’s own controls never managed.
Ironically, those 86 million accounts are a product of the market’s success. Non-cash transactions rose 40.74% year-on-year in the first two months of 2026, based on the SBV figures. Several banks say 95% of their transactions now go through digital channels. VietQR acceptance has reached around 2.1 million merchant outlets.
Vietnam built one of the busiest digital payments markets anywhere, and did it in under a decade. What has not kept pace is the infrastructure underneath: the identity checks, the fraud monitoring and the connections between them.
Fraud found the gaps first
The National Cybersecurity Association put consumer losses to online fraud at VND18.9 trillion for 2024, roughly US$744 million.
Police records show $1.5 billion has been lost across more than 24,000 cases since 2020, and the trend worsened through last year: Viettel Cyber Security logged 6.5 million compromised user accounts in the third quarter of 2025, 64% more than the quarter before, plus nearly 4,000 phishing domains dressed up as banks, government agencies and online shops.
Very little of that involved defeating a bank’s security outright. A mule needs a dormant account, and until September there were tens of millions to choose from. An impersonator needs a customer who was verified once, at onboarding, years ago.
A suspicious transfer requires a monitoring system that cannot detect a device change or a new beneficiary added the day before, because that information is stored elsewhere in the bank. The weak points sit between systems, not inside them.
Most Vietnamese banks are running technology designed for a card-and-branch business that has since been augmented with instant transfers, QR, wallets and e-commerce, one integration at a time.
Every addition made sense on its own. Together, they add up to an estate where a new fraud rule takes weeks to deploy and still covers only one channel, and where a good share of the technology budget goes to keeping old connections alive rather than building anything.
There is a point at which patching stops being the cheap option, once the maintenance bill and the losses leaking through the gaps are added together honestly. However, Vietnam’s transaction growth is pushing its institutions towards the crossover faster than most markets get there.
Regulation has picked a direction
The SBV has not been subtle about where it wants the industry to go. Facial biometric checks are mandatory for online transfers above VND10 million, and for total daily transfers exceeding VND20 million.
Its centralized fraud database, SIMO, connects 149 institutions; by mid-April 2026 it had pushed out 3.7 million warnings to customers, and over 1.2 million of them paused or abandoned a transaction as a result, keeping nearly VND4.17 trillion (about $158 million) out of criminal accounts.
Money is being directed too. Banks must now commit at least 15% of technology implementation budgets to cybersecurity and data security, a floor set in the banking sector’s 2026 digital transformation directive and repeated in the new Cybersecurity Law.
The Law on Data, the Personal Data Protection Law, and the Law on Digital Technology Industry, which came into force in January, put data handling and AI on a statutory footing for the first time.
Taken together, the expectation is plain enough: know who owns every account, share what you see and be in a position to stop a payment while it can still be stopped. Some banks have already jumped, including VPBank, LPBank and TPBank. VIB was first in the country to run its core banking on AWS, alongside a private cloud.
Payment rails are being rebuilt both outward and inward. Cross-border QR with China went live in December 2025, adding to working links with Thailand, Cambodia and Laos, and the State Bank announced the launch of a Vietnam–Singapore QR corridor in July, NAPAS’s sixth country connection.
Japan, South Korea and Malaysia are next on the list. Merchants gain a new customer base with each corridor; fraud, authentication and settlement teams gain a new jurisdiction, a second currency and no extra seconds to work with.
The trap in all this investment is obvious once named. A bank can migrate to newer technology and keep the old fragmentation, with issuing, authentication, fraud monitoring and servicing still in separate places.
Building for the new Vietnam
Over the past several years, I have worked with banks across Vietnam and the region on exactly this challenge: how to modernize payments infrastructure without disrupting growth, customer experience or day-to-day operations.
In Vietnam, the cloud-native SmartVista platform powered one of the first Visa Flexible Credential deployments in the market, enabling issuers to offer a single credential that lets customers switch between debit, credit, installments and reward options.
In practice, the product idea is rarely the hardest part. The real constraint is whether the underlying architecture can turn that idea into a secure, scalable service quickly enough.
PVcomBank offers another example of what the transformation looks like over time. The bank moved from its legacy core environment to a modular SmartVista stack, expanding its card issuing and management capabilities while connecting components through flexible APIs.
The platform now supports more than 1.1 million cards and processes an average of seven million transactions each month, alongside fraud management and 3DS 2.2 capabilities.
That growth would be much harder to manage on an estate where every new service requires another integration, another workaround and another operational dependency. The lesson is not that every bank needs the same technology, but that every bank needs an architecture capable of adapting as quickly as the market itself.
Next door in Cambodia, BPC took BIDC, a subsidiary of Vietnam’s biggest bank by assets, BIDV, live on SmartVista in March. One platform now covers BIDC’s issuing, acquiring, contactless EMV and fraud management and replacing the patchwork it ran before.
The bank now has real-time visibility across operations along with the ability to release new features without stopping anything else. We see Vietnamese banks working towards the same position, often on a much larger scale.
None of the deadlines will move while they get there. The Singapore corridor is open, more are scheduled and SIMO’s next reporting update will show which institutions are keeping pace. The clean-up of 86 million accounts dealt with the past.
What Vietnamese banks build over the next few years will determine far more than fraud outcomes. It will determine how quickly they can innovate, compete and earn customer trust in an increasingly digital economy.
Danny Duong, Ph.D., is managing director Vietnam at BPC. Over the past several years, he has worked with banks across Vietnam and Southeast Asia on payments infrastructure modernization, helping institutions rebuild core systems to support digital growth without disrupting operations.













