Our engineering team wrote this account of a security incident that happened over the holidays.
Our servers were attacked over Vietnamese New Year 2026 by a Vietnamese botnet.

It was the morning of February 18th, 2026, the second day of the week-long TαΊΏt (Lunar New Year) holiday in Vietnam. We had been looking forward to some quiet time off. Instead, the day started with urgent messages from our Samoa eCommerce team.
Payments were failing everywhere. Customers couldn't check out, and the business had effectively stopped.
The investigation
The whole team was offline for the holidays, but if you're responsible for the tech stack, you plan for this kind of morning. We grabbed our laptops, connected to the production servers from the hotel balcony, and put Brian, our AI agent, directly on the server to help work through the flood of logs.

Within minutes Brian found the cause, and it was a classic and humbling engineering oversight.
Two days earlier, on 16 February 2026, an automated scanner belonging to a roaming botnet had found an open port and tried to connect so it could turn our database into a replica. The connection failed in the end, but the repeated attempts triggered a defensive response that put the database into "Read-Only" mode.
The payment gateway's rate limiters wrote request counts to that same database, so once it went read-only, every API call returned an error and the system had in effect locked itself down.

Brian identified the culprit as a known variant of the 'i love u' malware script. With an AI assistant right there in the terminal, we patched the vulnerability, updated the firewall rules to block the botnet's IP range, and removed every trace of the malware in a fraction of the usual time.
The takeaway
Brian put it bluntly in its post-incident report: we were lucky. If nobody, human or AI, had been watching for anomalies over the long break, the damage could have been much worse.
Attackers count on this. They target holiday periods, when engineering teams are offline and slow to respond. It's an old playbook, and it nearly worked on us.
What saved us was having structured, centralised logs and an AI agent that could read them quickly. Together they turned what could have been a week-long disaster into an incident of a few hours. Which AI you use matters less than whether your monitoring and logging are in good enough shape for any tool to make sense of them under pressure.