
Late last year, a regional bank in Southeast Asia received an unusual email. Not from the attackers, but from their regulator. The supervisor had received an anonymous tip claiming the bank had suffered a major data breach two weeks earlier, with sample customer records attached as proof. The breach had happened. The bank had not yet finished its internal investigation, let alone disclosed it.
The attackers had taken the disclosure decision out of the institution’s hands.
That scenario, repeated quietly across the region in the past eighteen months, is the part of the ransomware story most ASEAN bank defences are not built for. The playbook the attackers are running today is not the playbook the banks have been training against, and the consequences are starting to show up in regulatory fines, customer notification disasters, and senior executive resignations that were preventable.
What the old playbook looked like
For most of the past decade, ransomware against banks worked in a predictable shape. Attackers gained access through phishing or unpatched vulnerabilities. They moved through the network. They encrypted critical systems. They demanded payment in cryptocurrency in exchange for a decryption key. The institution restored from backups when it could, paid quietly when it could not, and disclosed when it had to.
The defensive playbook was built around this model: offline backups, phishing training, network segmentation, ransom-payment policy, cyber-incident responder relationships. Most major banks across ASEAN have invested heavily here over the last five years. The investments were sound. They are not sufficient anymore.
Also Read: Singapore’s cybersecurity paradox: Leading in digital, lagging in defense
What changed in 2024-2025
Three shifts have happened, and they compound.
Data first, encryption second. Modern ransomware operators no longer begin with encryption. They begin with months of quiet exfiltration. By the time encryption runs, the attackers already hold a complete copy of the institution’s most sensitive data, customer records, internal communications, board materials, sometimes regulatory correspondence. Restoring from backup solves the operational disruption. It does nothing about the data the attackers still have.
Triple extortion. The single threat of decryption has become three threats in parallel. Pay or the data is released publicly. Pay or we sustain a denial-of-service against your customer-facing systems. Pay or we contact your most important enterprise clients directly. Each vector runs independently. Each has a different remediation cost. Banks built to negotiate against one threat are now negotiating against three.
Regulatory weaponisation. This is the shift most ASEAN supervisors are not yet talking about openly. Attackers have started using the institution’s own disclosure obligations as leverage. They contact the supervisor before the bank does. They release sample data publicly to force a notification clock. They threaten to alert the press, the regulator, and major enterprise customers simultaneously, knowing that the regulatory fine for delayed disclosure may exceed the ransom. The disclosure decision has effectively been transferred from the institution’s risk committee to the attacker’s keyboard.
Why ASEAN banks are more exposed
Three regional factors sharpen the exposure here.
Outsourced perimeter. Most ASEAN financial institutions have moved meaningful portions of their operational stack into third-party platforms over the past decade. The attackers have noticed. The entry point into a major bank now often runs through a smaller vendor with weaker security, and the dwell time inside the network is long enough that the attack is well-staged before the bank knows it has been compromised.
Disclosure rule asymmetry. Indonesia’s disclosure framework is lighter and more recently codified than Singapore’s. The Philippines and Vietnam are still building theirs. Attackers selecting targets can choose jurisdictions where regulatory pressure is high enough to weaponise but defensive cyber budgets are not at Singaporean levels.
Supervisor capacity. Banking supervisors and central banks across ASEAN have built cyber risk capability steadily but unevenly. Few of them have a standing capability to receive and triage attacker-initiated disclosures, which is exactly the channel the new playbook depends on.
What is starting to work
A few institutions are responding ahead of the curve.
Pre-staged disclosure plans. The banks handling this best now have legal, communications, regulatory, and executive escalation pre-staged for a scenario where disclosure is forced by an external actor rather than chosen internally. The plan does not eliminate the damage. It reduces the cost of the first seventy-two hours.
Adversary-aware tabletop exercises. The most useful incident response exercises I have seen in the past year simulate not just the technical attack but the multi-front pressure campaign that comes with it. The institutions running these exercises with their boards and regulators are surfacing gaps that purely technical drills do not.
Vendor risk visibility. The institutions tracking which vendors hold their data, with what controls, and under what notification obligations are catching threats earlier than those still treating vendor risk as a procurement question.
Also Read: The demand for SMB cybersecurity is inevitable, the supply was never built correctly
What needs to happen
Three moves would meaningfully shorten the gap.
Update incident response playbooks for forced disclosure. The assumption that the institution controls the timing of its own breach disclosure is no longer reliable. Plans should assume the attacker may move first, and rehearse for that scenario.
Harden the supervisory channel. Regulators should publicise a standardised process for attacker-initiated disclosures, and require banks to reciprocate with internal escalation triggers. The current ambiguity benefits the attackers.
Treat vendor security as systemic. The cyber resilience of a major bank is now functionally a property of the weakest critical vendor it depends on. Vendor risk and cyber risk are no longer separate problems.
The macro stakes
The ransomware threat against ASEAN financial institutions has moved out of the IT department and into the regulatory, legal, and reputational layers that sit above it. The defensive playbook still sits, in most institutions, with the technical teams. The next significant ransomware event in this region is unlikely to be lost in the data centre. It will be lost in the seventy-two hours after the attacker emails the supervisor.
The banks that win those seventy-two hours will be the ones whose CROs, CISOs, general counsels, and communications heads have already run the scenario together. The banks that lose them will be the ones still treating ransomware as an IT problem.
The playbook has changed. The defence needs to change with it.
—
Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.
The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.
Join us on WhatsApp, Instagram, Facebook, X, and LinkedIn to stay connected.
The post The new ransomware playbook: Why ASEAN banks are losing the disclosure war appeared first on e27.
