6 August 2026

On 20 July 2026, the Dewan Negara passed the Cybercrimes Bill 2026 (“Bill”). The Bill proposes to repeal the Computer Crimes Act 1997 (“CCA”) and replace it with a comprehensive legal framework to combat cybercrimes in Malaysia. It addresses contemporary and emerging cybercrimes driven by the rapid advancement of technology, the borderless nature of cyberspace, and increasingly sophisticated cyber threats.

This article sets out the key takeaways of the Bill.

Background

The CCA, enacted nearly three decades ago, is widely regarded as inadequate for the digital age. Its scope is limited to a narrow set of computer-related offences, such as unauthorised access to computer materials, wrongful communication of access codes, and unauthorised modification of computer contents. Crucially, the CCA lacks coverage for modern offences such as identity theft and misuse of artificial intelligence (“AI”), and relies on an outdated definition of “computer” that does not reflect modern technological infrastructure.

As cybercrime threats have evolved beyond traditional computer intrusions to encompass identity theft, online fraud, malware attacks, and the malicious use of AI, the legislative gap has widened. Upon commencement, the then Cybercrimes Act (“Act”) will bridge these deficiencies by introducing expanded definitions (such as replacing “computer” with “computer system” to include interconnected devices) and specific offences tailored to modern and emerging cyber threats. 

The Bill also aligns Malaysia’s domestic law with international instruments, including the Budapest Convention on Cybercrime and the United Nations Convention against Cybercrime. These treaties establish baseline standards for cybercrime legislation, cross-border cooperation, and procedural law.

Extra-territorial application

The Bill has extra-territorial application as it applies to any person regardless of nationality or citizenship. Offences committed outside Malaysia can be prosecuted as if they occurred within Malaysia, provided that:

  • the computer system, program, or computer data was located in Malaysia or connected to, sent to or used by the same or utilised a computer system, program, or computer data in Malaysia at the material time; or
  • the person affected by the offence is a Malaysian citizen.

Key offences

The Bill consolidates and expands upon the offences previously provided for under the CCA, while introducing new offences to address the evolving online landscape. We set out below an overview of the key offences, illustrated with real-world examples, and the corresponding penalties.

Offence

Criminalised activities

Penalty

Offences relating to confidentiality, integrity, and availability of computer system and computer data

Unauthorised access to computer systems

 

Base offence: Intentionally accessing a computer system without authority or lawful purpose.

Aggravated offence: Committing the base offence with the intention to either commit a further offence involving fraud or dishonesty or which causes injury, or to facilitate the commission of such further offence.

What could be covered: Basic hacking and more serious attempts aimed at committing fraud or causing harm.

Note: This provision expands the equivalent provision in the CCA by adopting the broader concept of a “computer system” in place of the narrower concept of a “computer”.

Base offence: Up to RM100,000 fine and/or three years’ imprisonment.

Aggravated offence: Up to RM500,000 fine and/or seven years’ imprisonment.

Unauthorised interception

 

Intentionally intercepting any private transmission of computer data without authority or lawful purpose.

What could be covered: Installation of spyware on a network to read private emails.

Up to RM500,000 fine and/or seven years’ imprisonment.

Interference with computer data

 

Intentionally and without authority or lawful purpose, damaging, deleting, or modifying computer data (including content data, traffic data and subscriber information), making it useless, interfering with its lawful use, or denying access to it.

What could be covered: Corrupting a database so that records are lost or unreadable.

Note: This provision expands the equivalent provision in the CCA regarding the unauthorised modification of computer contents.

Up to RM100,000 fine and/or three years’ imprisonment.

Interference with computer systems

 

Intentionally and without authority or lawful purpose, inputting, transmitting, damaging, altering etc. computer data to seriously hinder or interfere with the functioning of a computer system or the lawful use or operation of a computer system.

What could be covered: Launching a Distributed Denial-of-Service (DDOS) attack to crash a website or deploying ransomware that locks users out of their systems.

Up to RM500,000 fine and/or seven years’ imprisonment.

Misuse of device 

 

Dealings with device: Intentionally and without authority or lawful purpose, obtaining, producing, selling, distributing etc. devices including programs that are designed to commit cybercrimes or stolen passwords, with the intent to commit cybercrimes.

Possession of device: Possessing or controlling any such device or stolen passwords with the intent to commit cybercrimes.

What could be covered: Selling a “hacking kit” or a list of stolen login credentials on the dark web.

Dealings with device: Up to RM500,000 fine and/or seven years’ imprisonment.

Possession of device: Up to RM300,000 fine and/or five years’ imprisonment.

Offences relating to computer-related forgery and fraud

Computer-related forgery

 

Base offence: Intentionally and without authority or lawful purpose, creating or altering computer data to make inauthentic computer data appear authentic for the same to be acted upon for any legal purpose.

Aggravated offence: Where valuable security (i.e. a document that creates, transfers, or extinguishes any legal right) is involved in the base offence.

What could be covered: Falsification of a digital certificate.

Base offence: Up to RM300,000 fine and/or five years’ imprisonment.

Aggravated offence: Up to RM500,000 and/or seven years’ imprisonment.

Computer-related fraud

 

Intentionally and without authority or lawful purpose, altering any computer data, interfering with the computer system, or using a computer system to deceive someone into acting (or not acting) in a way that causes loss of property to another person with the intent to gain economic benefit.

What could be covered: Sending phishing emails that trick victims into transferring money to a scammer’s account.

Up to RM1,000,000 fine and/or ten years’ imprisonment.

Offences relating to national digital identity (“NDID”) service

Disclosure of passwords

Disclosure by a registered NDID service user of his passwords or access means, knowing that it will be used to commit a crime.

What could be covered: A user sells their MyDigital ID login details to a third party for illegal activities.

Up to RM100,000 fine or three years’ imprisonment.

Obtaining or supplying credentials for commission of offence

Obtaining, retaining, selling, supplying, or transmitting NDID credentials (including passwords, biometric identifiers, or digital certificates) of any registered NDID service user for criminal purpose.

What could be covered: A hacker sells a bundle of stolen digital identity credentials to facilitate identity theft.

First offence: Up to RM100,000 fine and/or three years’ imprisonment.

Second or subsequent offence: Up to RM300,000 fine and/or five years’ imprisonment.

Other offences

Wrongful communication

 

Communicating passwords or access codes to a computer system to any unauthorised person.

What could be covered: An employee shares their company’s administrator login details with an outsider who has no business need for them.

Note: This provision expands the equivalent provision in the CCA by adopting the broader concept of a “computer system” in place of the narrower concept of a “computer”.

Up to RM300,000 fine and/or five years’ imprisonment.

Identity theft

 

Intentionally and without authority or lawful purpose, using, obtaining, supplying, or possessing another person’s identity information via a computer system with the intention to commit or facilitate a crime.

What could be covered: Using stolen personal data to open a fraudulent bank account or apply for a loan in someone else’s name.

Up to RM500,000 fine and/or seven years’ imprisonment.

Transmitting generated or manipulated content

 

Transmitting, selling, or distributing audio or video content generated or manipulated using a computer system (which would include AI-generated content) that appears authentic or truthful, with the intent to commit or facilitate crime.

What could be covered: Creating and spreading a deepfake video of a politician making false statements to incite unrest or manipulate markets.

Up to RM500,000 fine and/or seven years’ imprisonment.

Dissemination of intimate images

 

Base offence: Sharing and distributing intimate images (including altered or manipulated images) of any person via a computer system.

Aggravated offence: Committing the base offence with the intention to cause humiliation or harm (including property damage, bodily injury, reputational or psychological harm) to, or to coerce or intimidate, the victim.

What could be covered: Sharing intimate photos of another person online or creating and distributing non-consensual intimate deepfakes of celebrities online.

Base offence: Up to RM300,000 fine and/or five years’ imprisonment.

Aggravated offence: Up to RM500,000 fine and/or seven years’ imprisonment.

Offences affecting or involving a national critical information infrastructure (“NCII”) or an NCII entity

Enhanced penalties for commission of any offences above (except dissemination of intimate images) which affect or involve an NCII or an NCII entity (as defined under the Cyber Security Act 2024).

Loss of life: Up to RM2,000,000 fine and/or 30-40 years’ imprisonment.

Injury to any person: Up to RM1,500,000 fine and/or 15 years’ imprisonment.

Other cases: Up to RM1,000,000 fine and/or 10 years’ imprisonment.

Attempt and abetment of offence

Attempting to commit or abetting the commission of any cybercrime.

As per the punishment provided for such offence.


Establishment of Committee on Combating Cybercrimes

The Committee on Combating Cybercrimes (“Committee”), chaired by the Chief Secretary to the Government, will be established once the Act comes into force. Members include representatives from the Treasury, the Attorney General’s Chambers, the Ministry of Home Affairs, the Ministry of Communications, and the Ministry of Digital. The Committee’s functions include planning and formulating anti-cybercrime strategies, advising the Government on policies, coordinating initiatives among enforcement agencies, assessing the effectiveness of existing mechanisms, and identifying gaps in the legal and enforcement framework.

Enforcement powers

The Act will come under the purview of the National Cyber Security Agency (NACSA), which operates under the National Security Council within the Prime Minister’s Department. Apart from police officers, any public officer or officer from the Malaysian Communications and Multimedia Commission (MCMC) may be authorised to exercise the enforcement powers under the Act.

The Bill grants extensive enforcement powers to the authorised officers, including:

  • Investigation powers: Authorised officers possess the powers of a police officer for investigating offences under the Act;
  • Search and seizure: Authorised officers may obtain warrants to search premises and seize computer systems, data, and devices. In urgent cases where delay might lead to evidence destruction, officers can conduct searches without a warrant.
  • Access to data: Authorised officers may require access to computer systems and data, and are empowered to demand passwords and encryption keys to access information;
  • Data preservation and disclosure: Authorised officers may issue written notices compelling expedited preservation of computer data and disclosure of computer data; and
  • Power to examine persons: Authorised officers may require any person acquainted with the case to attend for oral examination.

Jurisdiction to try offences

A Sessions Court has the jurisdiction to try any offence under the Act.

Service providers’ obligations

The Bill defines “service providers” broadly to include any person (whether or not licensed under the Communications and Multimedia Act 1998 (“CMA”)) who:

  • provides online communication service to its users;
  • processes or stores computer data on behalf of a communications service or the users thereof; or
  • provides information and communication services.

This broad definition captures a wide ecosystem of digital and telecommunication entities, which may include internet service providers, telecommunications operators, cloud service providers, social media platforms, internet messaging services, video conferencing tools, email providers, and web hosting companies.

Upon commencement of the Act, service providers have an ongoing general duty to take necessary measures to prevent their services from being used for cybercrimes.

Further, service providers must comply with the following specific duties on an ad hoc basis when required (whether pursuant to a request by authorised officers or the issuance of gazetted orders):

  • Compliance with regulatory notices: Service providers must comply with written notices issued by authorised officers to take specific actions (e.g. blocking access, removing content) to prevent cybercrimes;
  • Data retention: Service providers are required to retain certain computer data (i.e. traffic data and subscriber information) for a specified period to assist in investigations, in accordance with any gazetted orders;
  • Collection of traffic data: If required for any investigation, service providers are required to collect or record traffic data in real-time and provide such data to authorised officers;
  • Interception of content data: If required for any investigation, service providers are required to intercept or retain specific communications on its services, collect or record any content data within such communications, and assist the authorised officers in such interception or data retention; and
  • Confidentiality: Service providers must keep confidential any requests for data collection or interception made by authorised officers.

Failure to comply with any of the duties above may attract a fine up to RM1,000,000 (and in some instances, further daily fines of RM100,000 for continuing offences) and/or imprisonment of up to 10 years.

Service providers are however not liable for actions or omissions taken in good faith to comply with the Act.

Conclusion

The Bill represents a pivotal step in modernising Malaysia’s legal framework for cyberspace. It is the latest addition to a series of proactive legislative measures introduced in recent years, including the enactment of new legislation such as the Cyber Security Act 2024 and the Online Safety Act 2025 (“ONSA”), as well as amendments to existing laws such as the Penal Code and the CMA. Collectively, these efforts demonstrate Malaysia’s commitment to keeping pace with the rapidly evolving digital landscape and addressing emerging cyber threats.

Entities falling within the broad definition of “service providers” (whether or not licensed under the CMA) are required to implement necessary measures to prevent their services from being used for cybercrimes and cooperate with enforcement authorities in investigations (including the collection and interception of relevant data). It remains to be seen what measures are expected of service providers to fulfil the general duty as this is not elaborated on in the Bill.

Subscribers and users of the service providers’ services should be aware of the enhanced powers granted to enforcement officers, including the ability to intercept communications and access data without prior notice. Although a key driver for the introduction of the Bill is the urgent need to prevent harm from online scams and other cybercrimes, civil society organisations have raised concerns surrounding lack of independent oversight in relation to wide-sweeping enforcement powers, privacy, and censorship.