Article:

Vietnam’s New Digital Security Regulations: Strengthening Mobile and Biometric Protections

 

Vietnam is rapidly enhancing its digital security landscape. In just the past six months, two major regulations—Decision 2345 (effective July 2024) and Circular 50 (effective January 2025)—have been introduced to address growing threats such as biometric fraud, mobile app tampering, and unauthorized data access. These changes are not just regulatory updates; they serve as a wake-up call for businesses to fortify their cybersecurity defenses before it’s too late. 

 

Decision 2345/QD-NHNN: Strengthening Biometric Security 

Biometric authentication is becoming a standard for financial transactions and identity verification. However, its widespread adoption has also led to a surge in security threats. Deepfake attacks, Face ID spoofing, and breaches targeting citizen ID facial scans are becoming increasingly common. Cybercriminals exploit weaknesses in detection technologies, particularly the absence of iBeta Level 2 compliance, which is crucial for identifying virtual cameras and AI-generated faces. 

 

To combat these risks, V-Key Vietnam has been collaborating with clients and regulators since late 2022 to introduce V-Key ID—a solution designed to counter biometric fraud. It strengthens biometric security by detecting virtual camera injections, verifying the authenticity of biometric inputs, and proactively blocking deepfake-based attacks. V-Key’s Technology deployed by leading banks and Vietnam’s top fintech wallet super app, significantly reducing fraud incidents and unauthorized access.   

 

Circular 50/2024/TT-NHNN: Enforcing Mobile App Integrity 

With mobile banking usage at an all-time high, securing applications from tampering and malware is now a top priority. In response, the State Bank of Vietnam (SBV) has issued Circular 50, which mandates strict security measures for all mobile banking and financial applications. These requirements include: 

  1. Root detection – Preventing unauthorized modifications that could compromise an app’s security. 
  2. Source code protection – Blocking hackers from reverse-engineering mobile apps to exploit vulnerabilities. 
  3. Secure data exchange – Ensuring encrypted communication between mobile banking apps and online banking servers to mitigate the risk of man-in-the-middle attacks. 
  4. Tampering prevention – Implementing mechanisms to detect and prevent unauthorized alterations in installed mobile banking applications on customer devices. 

These measures are designed to enhance the resilience of digital banking and financial services against cyber threats. Organizations that fail to comply risk financial losses, reputational damage, and potential regulatory penalties. 

Notably, Circular 50 introduces risk-based authentication, requiring different authentication methods depending on the type and value of online transactions. For example, small-value transactions may use passwords or PINs, while higher-value transactions necessitate stronger authentication methods such as OTPs (via SMS, voice, or email), biometric verification, e-signatures, or FIDO2 authentication for enhanced security. 

 

V-Key ID: A Compliance-Ready Security Solution 

As Vietnam tightens its cybersecurity regulations, V-Key ID stands out as a ready-to-deploy solution that aligns with these new mandates. More than just a compliance tool, V-Key ID delivers robust security in an increasingly hostile digital environment. 

  1. Advanced Biometric Security
  • Fraudsters are leveraging deepfake technology to bypass facial recognition systems. V-Key ID detects and blocks AI-generated fraud attempts, ensuring only legitimate biometric inputs are accepted. 
  • Unlike traditional solutions,  V-Key ID is privacy-preserving because it does not send facial data to the server. It transforms the face biometrics into a private key that can then be used to authenticate remotely with a server. Facial data is only processed within the mobile app, hence protecting the biometrics privacy of the user. 

 

  1. Mobile Banking Protection with Anti-Tampering Measures
  • Mobile apps are prime targets for cybercriminals seeking to inject malicious code or manipulate app behavior. V-Key ID integrates root detection, app shielding, and anti-tampering mechanisms to ensure compliance with Circular 50. 
  • It defends against malware, unauthorized access attempts, and sophisticated cyber threats, providing financial institutions with confidence in their mobile platform security. 

 

  1. Privacy-Preserving AI Authentication
  • With data privacy concerns rising, particularly among foreign direct investment (FDI) firms and businesses handling sensitive user information, V-Key ID ensures that AI-driven identity verification occurs securely, minimizing exposure to data risks. 
  • By adopting AI privacy-preserving authentication, organizations can comply with stringent data protection laws while delivering a seamless user experience. 

 

  1. FIDO2 & Future-Proof Compliance for Digital Transformation
  • Traditional passwords are becoming obsolete, and phishing attacks are on the rise. V-Key ID fully supports FIDO2 standards, enabling passwordless authentication through biometric and cryptographic methods. 
  • As Vietnam’s digital transformation accelerates, V-Key ID is built to support evolving security needs while ensuring compliance with the latest regulatory requirements. 

 

  1. Why Leading Businesses Trust V-Key ID
  • Proven Track Record: Trusted by top banks, fintech companies, and government agencies, V-Key Technology has successfully protected millions of users worldwide. 
  • Cutting-Edge Security Technology: Our Virtual Secure Element (VSE) delivers hardware-grade security in a software-based solution, ensuring the highest level of protection. 
  • Adaptability & Scalability: Designed to seamlessly integrate with existing infrastructures, V-Key ID adapts to future security demands. 
  • Regulatory Compliance & Certifications: Holding Common Criteria EAL3+, FIPS 140-2, SOC2 Type II, and OATH certifications, V-Key ID meets international security standards, such as iBet 2 certification, aligning with bank-level security requirements. 

 

The Future of Digital Security in Vietnam 

Vietnam is raising the bar for cybersecurity with Decision 2345 and Circular 50, compelling financial institutions and digital businesses to take security seriously. The time to act is now—organizations must implement these measures before regulatory enforcement begins. 

V-Key ID provides a powerful, regulation-aligned security solution to protect businesses from fraud, ensure compliance with new laws, and support digital transformation initiatives. Whether it’s biometric authentication, mobile app shielding, AI privacy-preserving authentication, or FIDO2 passwordless security, V-Key ID is built to safeguard your digital ecosystem. 

 

Are you ready to strengthen your digital defenses? 

Contact us today—our expert team is available to provide tailored advice, help you navigate Vietnam’s evolving cybersecurity landscape, and ensure compliance with the latest regulations. Let’s build a safer future together. 

Article
Building Digital Trust with V-Key at the State Bank of Vietnam Event 

2025 April, Vietnam –  V-Key had the privilege of participating in the State Bank of Vietnam (SBV) CIO Roundtable event on 1 April 2025. This event brought together key players in Vietnam’s financial industry to discuss the future of banking security and the impact of regulations on digital transformation. It was an important platform to explore how V-Key supports financial institutions in Vietnam to stay ahead of regulatory compliance and security innovation. 

Article
Journey to Passwordless Authentication

Is it the Beginning of the End of Passwords? 

In the wake of cyber-attacks at some of the biggest Superannuation Funds in Australia last week, one question should be asked, is this the beginning of the end of Passwords? The safety of using Passwords has been broken for a long time. Managing passwords can be dauntingly challenging. They can be difficult to remember, and often, people reuse them across multiple platforms and systems, which makes them a target for cybercriminals. In fact, according to the 2023 Verizon Data Breach Investigations Report (DBIR), over 50% of data breaches are linked to stolen or compromised credentials. This exposes sensitive data, whether it’s banking details, emails, or personal information, to potential risks.  

Article
Mobile Malware Landscape in 2024: Why App Security Is Critical for Businesses

Mobile malware attacks are rising as mobile banking, digital payments, and remote authentication become mainstream. In 2024, over 33.3 million mobile malware attacks were recorded globally, according to a report by a security firm, underscoring the urgent need for stronger mobile security. Another study found that Trojan banking malware attacks nearly tripled this year, surging by 196% worldwide. 

Article
Strengthening Australia’s Digital Identity Future 

Australia is making significant progress in digital identity adoption, with the federal government leading efforts through its national Digital ID system. 73% of Australians now have a Digital ID account for government services, up from 60% in 2023, reflecting increasing engagement. With smartphones as the most popular device for accessing these services, digital identity is becoming a key part of everyday interactions. However, 56% of Australians remain concerned about data security, highlighting the need for a secure and seamless identity ecosystem. 

Article
Beyond OTPs: The Shift to Passwordless Authentication in Banking

The Bangko Sentral ng Pilipinas (BSP) is considering phasing out one-time passwords (OTPs) for digital banking transactions, citing the growing vulnerabilities of this method. BSP Deputy Governor Elmore Capule emphasized that the agency is exploring stronger security measures to make digital banking more resilient, with biometric authentication and other advanced technologies being evaluated as secure alternatives to OTPs.

Article
V-Key Continues to Expand in Australia to Strengthen Digital Identity and Authentication

V-Key strengthens its presence in Australia by participating in the FIDO Alliance events in Melbourne, reinforcing its commitment to digital identity and authentication. With discussions on passkeys, step-up authentication, and regulatory updates, V-Key highlighted how V-Key ID enhances security and trust. As digital transformation accelerates in Australia, V-Key continues to support enterprises in financial services, payment gateways, and government with innovative mobile security solutions. Expanding its local team, V-Key is dedicated to enabling seamless and secure digital interactions through advanced authentication technologies.

Article
Why Passwordless Authentication is the Future of Security

Managing passwords can be challenging. They can be difficult to remember, and often, people reuse them across multiple sites, which makes them a target for cybercriminals. In fact, according to the 2023 Verizon Data Breach Investigations Report (DBIR), over 50% of data breaches are linked to stolen or compromised credentials. This exposes sensitive data, whether it’s banking details, emails, or personal information, to potential risks. 

Article
Protect Your Business All Year with V-Key ID and FIDO2

Lunar New Year is a time for celebration for many people around the world, but it’s also a good opportunity for scammers who are always trying to entice victims to grab the next cheap online shopping deal. A common technique that scammers use is to lure a victim into installing a malware app that can then be used to phish user’s credentials, capture SMS OTPs, or even remotely control the phone to perform banking transactions. 

Article
V-Key’s 2024 Journey in Advancing Digital Security and Empowering Seamless Digital Experiences

As we reflect on 2024, V-Key is proud of the milestones we’ve achieved and the innovations we’ve introduced in the field of digital identity and mobile security. This year, we have remained steadfast in our mission to protect digital experiences and empower businesses with advanced solutions. From key industry events to groundbreaking technological advancements, we’ve continually strived to meet the evolving needs across various sectors.  

Article
5 Simple and Effective Ways to Secure Your Mobile App with V-OS App Shield

For businesses, especially those handling sensitive data or financial transactions, ensuring app security is no longer optional. The risk is real: attacks on mobile apps can lead to reputational damage, regulatory fines, and the loss of user trust.  

V-OS App Shield is a reliable solution designed to safeguard mobile applications. Beyond the basics of security, it offers a cost-effective approach that combines robust protection with ease of use. Here are 5 ways V-OS App Shield can enhance your mobile app security and deliver real-world benefits. 

Article
Securing Mobile Apps and Why It’s Critical for Businesses

Mobile devices continue to become indispensable, with the average smartphone user spending around 88% of their day interacting with apps. This surge in mobile usage highlights an escalating need for businesses to ensure their apps are secure, as the stakes of app security have never been higher. From retail businesses to e-commerce platforms, mobile apps handle sensitive user data and provide access to essential business systems. The consequences of a breach can be devastating, both for businesses and their users. 

Article
Introducing V-OS App Shield: Connect, Deploy and Protect your App in Minutes

Mobile applications are key to daily business operations, customer engagement, and overall functionality. According to Google, the average smartphone user interacting with nearly 10 apps daily and spending about 88% of their time on mobile, the need for strong mobile app protection has never been more pressing. Introducing V-OS App Shield, a revolutionary solution designed to secure your mobile apps fast and easy.

Article
V-Key partners with Bridge Alliance to build a Safer Digital Ecosystem

V-Key, renowned for its advanced security solutions has proudly joined Bridge Alliance as their technology Partner,  solidifying their commitment to innovation and excellence in mobile security. This partnership opens doors to explore new avenues for enhancing authentication experiences and mitigating cybersecurity risks.

Article
Making 2FA/MFA robust against smishing and related attacks

2FA/MFA was introduced to make it harder for attackers, by requiring two or more proofs of identity – also known as authentication factors. These can take many forms, but can be boiled down to: something you know (e.g., a password), something you have (e.g., a cryptographic key), or something you are (e.g., a biometric ID that is unique to you) [1].

However, 2FA/MFA is not a universal panacea that can be picked off a shelf and thrown in to solve any and all challenges presented by attackers.

Article
How do we determine the effectiveness of mobile apps’ security systems?

With the spate of remote working regime due to Coronavirus pandemic, the reliance and growth for video conferencing platform has been exponentially escalated. However, most mobile apps today are nowhere near as secure as we would like them to be.

Article
Is the detection of jailbroken/rooted phone sufficient against threats?

Functions that detect jailbroken/rooted devices are most commonly added to transactional mobile applications, serving as the most basic defense against threats. However, this is nothing but a drop in a bucket.

Article
Why Existing Mobile Software Protections are Insufficient

Recognizing that existing mobile software protections are insufficient against today’s cyber threat landscape, we take a closer look at the main types of software protections in the market.

Article
V-OS Protection against CPU vulnerabilities

Virtually every computing device in the world is made unsafe by the latest disclosures on Central Processing Unit (CPU) vulnerabilities. Find out how the virtual secure element technology is protecting millions of mobile application users against such vulnerabilities.

Article
V-OS Protection against Android Plugin malware

There has been a recent surge in Android malware abusing Android Plugin Frameworks for malicious behavior. DroidPlugin, Parallel Space and VirtualApp are several plugin frameworks that have been abused by malware in recent months to spread Android malware.

Article
Three steps to fight the Mobile Security status quo

Have financial institutions accepted a status quo that sacrifices user experience for increased security? With mobile digital identity quickly becoming central to an entire suite of online services, those who challenge the status quo will set themselves up to prosper and grow. Read more to find out three oft-ignored areas of research.

Article
Cryptography in V-OS

V-OS is the world’s first virtual secure element. Cryptography plays a dual-role in these; to secure and manage the secrets kept within V-OS, and to provide a lightweight yet comprehensive cryptographic library.

Article
Building V-OS with HSM

V-OS is the world’s first virtual secure element, a software solution with security built into the firmware code. These include secret cryptographic parameters and data, which need to be randomly generated and securely persisted, and are then transformed into code and data files.

Article
How does a Virtual Smart card protect a customer if they lose or change their mobile phone?

From banks to government agencies, many organisations are intrigued by and exploring software security solutions such as mobile tokens and mobile identity systems for individual identification, authorisation and authentication.

Article
Is software-based Biometrics Authentication the solution to ASEAN’s regulatory challenges?

Banks in Southeast Asia should look towards software-based biometrics as the way forward to navigate the regulatory differences in the region and secure their customers’ transactions.

Article
Infographic: The next frontier in Banking transformation

As technology evolves, banks and financial institutions have no choice but to innovate. However, when it comes to security, many still rely on traditional, costly methods.

Article
Mobile Security that works for everyone

Safe, convenient and simple.

Article
The next wave of Finance: Singapore’s growing Fintech market

With global cumulative investment in financial technology (fintech) forecast to exceed US$150 billion in three to five years, economies around the world are vying to attract fintech innovators and cash in on this growing industry.