So, what type of company is most vulnerable to cybersecurity incidents?
A major financial institution in Indonesia was hit by ransomware and experienced a data breach. In the United States, a technology company suffered a data breach affecting 73 million customers.
On the other hand, Kaspersky found that 92% of MSMEs in Indonesia experienced a cyber incident in the past year, the third-highest rate in Asia Pacific after Vietnam and Malaysia.
So, which is more vulnerable, MSMEs or large enterprises? The answer is both.
Fraud is democratic. It does not choose its next target based on the size of an organization. It attacks whatever security gaps are left open.
Fraud Doesn’t Care About Company Size
VIDA Founder and Group CEO Niki Luhur made this point during a panel discussion at Money20/20 Asia 2026.
“Cybercrime is democratic. They don’t care how big your institution is. They simply scan for vulnerabilities. Any door that is left open will be exploited. Whether you’re a small fintech, a small startup, or a large bank, they’re simply looking for whichever door they can open.”
This shows that fraudsters do not assess targets based on business size. They look for whatever vulnerabilities they can exploit.
Meanwhile, according to Kaspersky Head of Unified Platform Product Line Ilya Markelov, sophisticated cyberattacks can easily penetrate systems when security defenses are fragmented.
This means both small and large companies can be vulnerable, albeit for different reasons. Smaller companies may have less comprehensive security systems, while larger enterprises can be exposed to the complexity of multiple tools that are not fully integrated.
What Is Fraud-as-a-Service?
Fraud-as-a-service is a useful way to describe this shift. Today, fraudsters can simply rent or buy readily available tools for creating fake identities and then run fraud operations much like an organization.
On the ground, fraud has evolved into an organized industry. Niki explains that these operations are already supported by data science teams. This is no longer the work of an individual hacker, but of cross-border syndicates operating at an industrial scale.
This makes comparing companies by size less relevant. Both types of businesses are facing organized criminal operations with resources that operate at an industrial scale.
VIDA research in its 2026 SEA Digital Identity Fraud Outlook whitepaper shows how quickly and cheaply fraud can scale. The cost of creating a complete synthetic identity package, including a photo, identity document, and biographical data, fell from around US$15 in 2022 to less than US$0.001 in 2026. When the cost of production approaches zero, the potential volume of attacks becomes virtually unlimited.
VIDA research also shows that security teams have less time to respond to AI threats. In 2023, security teams had around 12 months to prepare defenses before a more advanced AI model emerged. By 2026, that window had shrunk to around two weeks. This means defenses built last month could already become ineffective before they are fully deployed.
This should change how businesses assess risk. Companies can no longer assess risk based on business size. The answer is clear: any business can become a target. The focus should shift toward building security infrastructure that continuously monitors transactions and verifies users throughout the process.
If fraudsters exploit vulnerabilities regardless of company size, defenses should be built across the same layers for businesses of every size.
For more information, contact the VIDA sales team https://vida.id/id/sales