29 July 2026

On 1 July 2026, the Cybercrimes Bill 2026 (“Bill”) was passed in the Dewan Rakyat. The Bill has yet to be passed by the Senate.

The main objectives of the Bill are to:

  • repeal the Computer Crimes Act 1997 (“CCA”) in its entirety;
  • align domestic legislation with international frameworks such as the Budapest Convention on Cybercrime and the United Nations Convention against Cybercrime;
  • address emerging cybercrime threats, including AI-generated misinformation and identity theft; and
  • equip authorised officers with enhanced enforcement powers.

A summary of the key provisions is set out below.

Establishment of Committee on Combating Cybercrimes

The Bill seeks to establish a Committee on Combating Cybercrimes (“Committee”), comprising members from various ministries and government departments. The Committee’s mandate will include planning and formulating anti-cybercrime strategies, advising the Government on policies and coordinating initiatives among enforcement agencies, assessing the effectiveness of existing mechanisms, and identifying gaps in the legal and enforcement framework.

Key offences

The Bill seeks to modernise Malaysia’s cybercrime framework by introducing new offences and expanding existing offences to address evolving digital threats. Some of the key offences are set out below:

  • Unauthorised access to computer systems;
  • Unauthorised interception of private communications;
  • Interference with computer data or computer systems;
  • Misuse of devices including programs designed to commit cybercrimes;
  • Computer-related forgery or fraud;
  • Unauthorised disclosure of passwords or grant of access to the national digital identity (“NDID”) service;
  • Obtaining or supplying NDID credentials for criminal purpose;
  • Wrongful communication of passwords or access codes;
  • Identity theft;
  • Transmission of AI-generated or manipulated content to commit or facilitate a crime;
  • Dissemination of intimate images; and
  • Enhanced penalties for the commission of a cybercrime affecting or involving a national critical information infrastructure (“NCII”) or an NCII entity as defined under the Cyber Security Act 2024.

Enhanced enforcement powers

The Bill empowers the Minister to authorise public officers or officers from the Malaysian Communications and Multimedia Commission to enforce its provisions. These authorised officers:

  • are vested with the full investigative powers of a police officer provided for under the Criminal Procedure Code;
  • may search premises and seize computer systems, data, and devices with or without a warrant, depending on the urgency of the case;
  • may compel the provision of passwords, encryption or decryption codes, and software or hardware to access information;
  • may issue written notices for the expedited preservation of computer data and disclosure of computer data; and
  • may require attendance of, and examine orally, persons acquainted with a case.

Repeal of the CCA

The Bill proposes the repeal of the CCA, which has been widely regarded as being inadequate to safeguard the public against modern threats such as ransomware, online fraud, identity theft, non-consensual deepfakes, and AI-generated misinformation.