Ransomware Attacks On Southeast Asian SMBs Rise In Q1 2026, Kaspersky Reports

Low Boon Shen
3 Min Read

Kaspersky data shows that ransomware remains a prevalent threat to small and medium-sized businesses (SMBs) in the Southeast Asia region, with 3.51% of SMBs across the region targeted in Q1 2026, up from 2.92% in Q1 2025. In Malaysia, the proportion of SMBs targeted rose to 2.74%, compared to 2.09% in the same period last year.

India and Indonesia recorded the largest increases in the region, rising from 3.18% to 4.07% and from 2.83% to 4.01% respectively. Singapore also logged a modest rise, from 0.57% to 0.69%. The Philippines, Thailand, and Vietnam recorded declines during the same period. Below is the full list of figures:

CountryQ1 2025Q1 2026
India3.18%4.07%
Indonesia2.83%4.01%
Malaysia2.09%2.74%
Philippines2.46%1.80%
Singapore0.57%0.69%
Thailand1.28%1.12%
Vietnam2.91%2.56%
Southeast Asia2.92%3.51%

Ransomware Increasingly Target SMBs

Kaspersky said the steady continuation in the proportion of SMBs attacked, rather than the modest year-on-year changes, reflects the sustained nature of the threat; the company noted that its detection metric only captures the final stage of a ransomware attack – the deployment of the encryption Trojan – meaning attacks intercepted earlier during initial access, reconnaissance, discovery, or lateral movement are not reflected in the statistics, so the extent of ransomware proliferation is worse than what the numbers would suggest.

The company’s Q1 2026 malware report identified Clop ransomware as the most prolific group, accounting for 14.42% of victims published on Dedicated Leak Sites (DLS) under review, followed by Qilin at 12.34%. A newer group, The Gentlemen, ranked high up in third despite emerging only in July 2025. Kaspersky said the group uses custom-built tools for covert information gathering before deploying ransomware and likely collaborates with Initial Access Brokers (IABs) to gain access to target organizations.

Contrary to common belief, backup is not the silver bullet against ransomware attacks, as Kaspersky security expert Fedor Sinitsyn points out. Threat actors now use a double extortion approach involving both file encryption and data exfiltration, the latter of which is especially problematic if data involved is sensitive by nature. As such, a layered cybersecurity strategy is needed to provide adequate protection against such attacks.

For SMBs, here are the best practices: always keep software updated to patch up exploits, as our government learned this the hard way; pay attention to internet and network traffic for suspicious outgoing activity; set up isolated offline backups; set up EDR software for threat detection (any reputable vendor works); and develop an incident response plan should the worst happens.

Pokdepinion: Ransomware is unfortunately a lucrative business for crime organizations, so defense is the best and only strategy available for SMEs and major organizations alike.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *