Overview

The Cybercrimes Bill 2026 comes at a crucial time, in a world full of deception and tricks — enhanced by AI and other technology. The bill repeals the outdated Computer Crimes Act 1997, which has been in force for more than 30 years and came about as a result of the MSC initiative by the Malaysian government. The new Cybercrimes Act 2026 will provide more complete protection against identity theft, deepfakes, online fraud, and scams.

The Cybercrimes Bill 2026 (Rang Undang-Undang Jenayah Siber 2026) was tabled for its first reading in the Dewan Rakyat on 22 June 2026 by Deputy Prime Minister Datuk Seri Dr Ahmad Zahid Hamidi. It represents the most substantial overhaul of Malaysia's cybercrime legislation since the Computer Crimes Act 1997 (Act 563) — the foundational statute it is designed to repeal and replace. Once enacted, its short title will be the Cybercrimes Act 2026.

The government's rationale, set out in the Bill's own explanatory statement, is that the reform is necessitated by the rapid advancement of digital technology, the borderless nature of cyberspace, and the increasing sophistication of cybercrime activities that threaten national security, the economy, public order and the safety of persons. Cybercrime today extends well beyond hacking to encompass identity theft, organised online fraud, ransomware, the exploitation of generative AI, and deepfake-enabled deception.

Put plainly: in the golden age of AI in 2026, digital technology is advancing at the speed of light — and the law has been racing to keep up. Forgery and deepfake tools that were once the domain of specialists are now in almost everyone's pocket. With just a few taps on a phone, anyone can generate a convincing fake document, a cloned voice, or a fabricated image. That is exactly the reality the Computer Crimes Act 1997 was never built for, and exactly the gap this Bill sets out to close.

Structurally, the Bill comprises eight Parts and 61 Clauses. It establishes a Committee on Combating Cybercrimes to coordinate national strategy, and the Chief Executive of the National Cyber Security Agency (NACSA) serves as the Committee's secretary and runs an integrated information system for cybercrime intelligence.

Update (1 July 2026): the Dewan Rakyat passed the Bill on a majority voice vote after a debate involving 48 government and opposition MPs. During the debate, members raised concerns about the breadth of investigators' powers to access data, privacy safeguards, and the need to define AI-generated content carefully so that satire, artistic work and political criticism are not caught. Winding up, Deputy Prime Minister Datuk Seri Dr Ahmad Zahid Hamidi stressed that the powers are not absolute — access to computer systems and data must follow prescribed legal procedures, and data disclosure requires a written notice tied to a lawful investigation. The Bill now proceeds to the Dewan Negara.

The Next Chapter of the MSC Malaysia Cyber Law Framework

The Computer Crimes Act 1997 was one of the five original cyber laws enacted under the MSC Malaysia Bill of Guarantees. Its replacement by the Cybercrimes Bill 2026 marks the next chapter of that framework — preserving Malaysia's long-standing commitment to legal certainty in the digital economy while modernising it for AI-era threats.

Important — Passed by the Dewan Rakyat, Not Yet in Force

This page is a public reference resource and does not constitute legal advice. On 1 July 2026 the Bill was passed by the Dewan Rakyat, but it is not yet law. It must still pass the Dewan Negara (Senate), receive Royal Assent, be gazetted, and be commenced by the Minister on a date appointed by notification in the Gazette. Its provisions may also be amended along the way. Until commencement, the Computer Crimes Act 1997 remains the law in force. For the authoritative text once enacted, refer to the Attorney General's Chambers of Malaysia, and consult a qualified Malaysian advocate and solicitor for any specific matter.

Legislative Status & Timeline

The Bill has moved quickly. It was passed by the Dewan Rakyat on 1 July 2026 following debate by 48 MPs, but under Clause 1 the Act comes into operation only on a date appointed by the Minister by notification in the Gazette — so passage in the lower house is not the same as the law taking effect. It must still clear the Dewan Negara, receive Royal Assent, and be gazetted and commenced. Until then, the Computer Crimes Act 1997 remains the operative law.

22 Jun 2026
First reading in the Dewan Rakyat; Bill formally introduced and published.Completed
1 Jul 2026
Passed by the Dewan Rakyat on a majority voice vote after debate by 48 MPs across government and opposition.Passed
Next
Dewan Negara (Senate) reading, then Royal Assent, gazettement, and a commencement date appointed by the Minister before the Act takes effect. With the Bill already through the Dewan Rakyat and backed by the government, it is widely expected to clear these remaining formalities and become law in the near term.Expected soon

Key Offences Under the Bill

Here is where the Bill stops being abstract. Its offences live in Parts III to VI, and what strikes you reading them is how closely they map to the scams and harms Malaysians actually run into — the drained bank account, the fake nude, the borrowed login, the cloned voice on the phone. Below are the ones that matter most, with the penalties taken straight from the Bill as tabled.

One thread runs through nearly all of them, and it is worth holding onto as you read: an act only becomes an offence when it is done intentionally and without authority or without lawful purpose. In other words, the Bill is aimed at people who set out to deceive or harm — not at the researcher, the journalist, or the ordinary user who stumbles into something innocently. That intent requirement is the line between a crime and an accident, and it appears again and again below.

Cl. 10

Access to a Computer System Without Authority

This is the foundation stone — the modern successor to the old Section 3 of the 1997 Act. It covers intentionally getting into any part of a computer system you have no authority or lawful reason to enter. Think of someone logging into an account that isn't theirs, or slipping past a login they were never meant to pass. It doesn't matter whether they were after any particular file or program; simply securing the access without permission is the offence. It's the entry point that so many bigger crimes start from, which is why the Bill treats plain unauthorised access as wrong in itself, before any further harm is even attempted.

Up to RM 100,000 or 3 years' imprisonment or both
Cl. 11

Unauthorised Access With Intent to Commit a Further Offence

This is the same break-in, but with a darker purpose behind it. Where someone gains access not just to snoop, but as a stepping stone to something worse — fraud, dishonesty, or causing injury as defined in the Penal Code — the law comes down harder. The reasoning is intuitive: breaking into a system to steal money or hurt someone is far more serious than wandering in out of curiosity, so the penalty roughly doubles. It's the difference between trespassing and breaking in to commit a robbery.

Up to RM 500,000 or 7 years' imprisonment or both
Cl. 12–15

Interception, Data & System Interference, Misuse of Device

This cluster covers the classic toolkit of hacking. Interception (Cl. 12) is the digital equivalent of wiretapping — secretly capturing data as it travels to, from or within a system. Data interference (Cl. 13) is tampering with the information itself: deleting, corrupting or locking files, which is exactly what a ransomware attack does. System interference (Cl. 14) goes after the machine's ability to function at all — think of an attack that knocks a service offline. And misuse of device (Cl. 15) reaches back a step further, to the people who make, sell or stockpile the hacking tools, stolen passwords and access credentials that the other offences rely on. By criminalising the supply chain, the Bill tries to choke off attacks before they happen.

Up to RM 500,000 / 7 years (interception, system interference, misuse) · RM 100,000 / 3 years (data interference) · possession: RM 300,000 / 5 years
Cl. 16

Computer-Related Forgery

Forgery is an old crime that has simply moved online. Instead of faking a signature on paper, someone alters or fabricates computer data so that false information passes as genuine — a doctored contract, a tampered record, a fake certificate meant to be relied on for a legal purpose. The penalty steps up when a "valuable security" is involved, meaning a document that creates or transfers real legal rights, because the potential for harm is that much greater. It's the digital version of putting your name on something that was never truly yours to sign.

RM 500,000 / 7 years (valuable security) · RM 300,000 / 5 years (other cases)
Cl. 17

Computer-Related Fraud

If any single clause is aimed at the scam epidemic, it's this one — and the penalty, the heaviest of the standard offences, tells you how seriously the government takes it. It covers manipulating data or a system, or deceiving someone through a computer, in order to cause them financial loss while dishonestly enriching yourself or another. This is the legal net cast over the investment scams, fake job offers, phishing operations and mule-account rackets that have cost Malaysians billions. Where the old law strained to fit these schemes into decades-old wording, this clause names the harm directly: online deception for profit.

Up to RM 1 million or 10 years' imprisonment or both
Cl. 19

Disclosing a National Digital Identity Password

As Malaysia moves toward a national digital identity, your MyDigital ID becomes a master key to a great deal of your life — which is exactly why handing it over is now its own offence. If a registered user gives away their digital identity password, or otherwise lets someone act in their identity, knowing (or having good reason to suspect) it will be used for a crime, they're on the hook. There's a sting in the tail worth noting: if you did it for gain, the law presumes you knew what it would be used for, and it's on you to prove otherwise. The message is blunt — your digital identity is not something to lend out, not even "just this once."

Up to RM 100,000 or 3 years' imprisonment or both
Cl. 20

Obtaining or Supplying a User Credential

Where the previous clause targets the person who gives their own identity away, this one goes after the trade in other people's. Obtaining, keeping, supplying or passing around someone's digital-identity credentials — including biometric data and digital certificates — for use in a crime is an offence, and a repeat offence carries a heavier penalty. This is aimed squarely at the market that fuels identity fraud: the sellers and brokers of stolen credentials who never commit the final scam themselves but make it possible.

RM 100,000 / 3 years · second offence: RM 300,000 / 5 years
Cl. 22

Identity Theft

Your identity is now one of your most valuable — and most stolen — possessions. This clause makes it an offence to use a computer to obtain, supply, use or even just hold someone else's identity information with the intent to commit or facilitate a crime. The definition of "identity information" is deliberately wide: anything that identifies, or even purports to identify, a person. That breadth matters, because identity thieves are endlessly inventive, and a narrow definition would leave gaps for them to slip through. It's a direct answer to the mule-account recruiters and impersonation syndicates that have become so common.

Up to RM 500,000 or 7 years' imprisonment or both
Cl. 23

Synthetic & Manipulated Content (Deepfakes)

This is one of the most forward-looking parts of the whole Bill, and the reason it feels so timely. It targets AI-generated or manipulated audio and video — content made to resemble a real person, place, object or event, and passed off as authentic to help commit a crime. The scam call in a loved one's cloned voice, the fake video of a public figure "endorsing" an investment, the doctored clip used to trick a victim into paying: these are the harms it's built for. Crucially, it's not the technology that's criminalised — using AI is not itself an offence — but the deceptive, harmful use of it. Intent and purpose are still what turn a clever fake into a crime.

Up to RM 500,000 or 7 years' imprisonment or both
Cl. 24

Dissemination of Intimate Images

This clause confronts one of the cruelest abuses of the AI era. It's an offence to share, publish or sell a person's intimate image through a computer system — and, importantly, the Bill's own explanatory statement makes clear that an "intimate image" includes content that is AI-generated, deepfaked or synthesised. In other words, the old defence of "but it isn't really her, I made it" no longer holds: a fabricated nude is treated the same as a genuine one, because the humiliation and harm to the victim are just as real. The penalty rises sharply when the aim is to humiliate, harm, coerce or intimidate the person depicted — recognising that this is often less about images than about power and cruelty.

Base: RM 300,000 / 5 years · Aggravated: RM 500,000 / 7 years
Cl. 25

Offences Affecting Critical Information Infrastructure

Some targets are simply too important to treat like any other. When one of these offences strikes national critical information infrastructure — the systems behind power, water, banking, healthcare, telecommunications, as defined in the Cyber Security Act 2024 — the penalties become the most severe in the entire Bill. The reason is sobering: an attack on these systems can ripple out into the physical world, disrupting essential services and even endangering lives. That's why the law reserves its harshest response, up to forty years' imprisonment where loss of life results, for those who would turn a cyberattack into a threat against the nation itself.

Loss of life: 30–40 years + up to RM 2 million · Injury: up to 15 years + RM 1.5 million · Otherwise: RM 1 million / 10 years

Structure — The Eight Parts

The Bill is organised into eight Parts spanning 61 Clauses, set out in its arrangement of clauses as follows.

PartCoverage
Part IPreliminary — short title and commencement, extra-territorial application, and definitions (Clauses 1–3).
Part IICommittee on Combating Cybercrimes — establishment, membership, functions, meetings and subcommittees (Clauses 4–8).
Part IIIOffences relating to the confidentiality, integrity and availability of computer systems and data — access, interception, data and system interference, misuse of device (Clauses 9–15).
Part IVComputer-related forgery and computer-related fraud (Clauses 16–17).
Part VOffences relating to the National Digital Identity Service — disclosure of passwords and credential offences (Clauses 18–20).
Part VIOther offences — wrongful communication, identity theft, synthetic/manipulated content, intimate images, and critical-infrastructure aggravation (Clauses 21–25).
Part VIIEnforcement — authorisation of officers, investigation, search and seizure, data preservation and disclosure, real-time traffic collection and interception, jurisdiction (Clauses 26–49).
Part VIIIMiscellaneous — integrated information system, service-provider duties, data retention, court orders, liability, and the repeal of the 1997 Act (Clauses 50–61).

The Committee on Combating Cybercrimes

A genuinely new feature of the Bill, absent from the 1997 Act, is a high-level coordinating body. Part II establishes the Committee on Combating Cybercrimes, chaired by the Chief Secretary to the Government with the Director General of National Security as deputy. Its membership spans the Attorney General, the Inspector-General of Police, Bank Negara, the Securities Commission, the Companies Commission, the Personal Data Protection Commissioner, the National Anti-Financial Crime Centre, and the MCMC, among others.

The Committee's role is strategic rather than prosecutorial: to plan and decide national approaches to preventing and combating cybercrime, advise the Government on policy, coordinate enforcement agencies, assess the effectiveness of existing mechanisms, and identify gaps in the legal framework. The Chief Executive of NACSA serves as its secretary.

Penalties at a Glance

Penalties scale with the seriousness of the conduct. The figures below are drawn directly from the Bill as tabled and are subject to amendment in debate.

OffenceClauseMaximum penalty
Access to a computer system without authorityCl. 10RM 100,000 / 3 years
Access with intent to commit further offenceCl. 11RM 500,000 / 7 years
Interception without authorityCl. 12RM 500,000 / 7 years
Computer data interferenceCl. 13RM 100,000 / 3 years
Computer system interferenceCl. 14RM 500,000 / 7 years
Misuse of device (making available)Cl. 15(1)RM 500,000 / 7 years
Computer-related forgeryCl. 16RM 500,000 / 7 yrs (valuable security); RM 300,000 / 5 yrs (other)
Computer-related fraudCl. 17RM 1 million / 10 years
Disclosing a digital identity passwordCl. 19RM 100,000 / 3 years
Wrongful communication of accessCl. 21RM 300,000 / 5 years
Identity theftCl. 22RM 500,000 / 7 years
Synthetic / manipulated content (deepfakes)Cl. 23RM 500,000 / 7 years
Dissemination of intimate imagesCl. 24RM 300,000 / 5 yrs base; RM 500,000 / 7 yrs aggravated
Offence affecting critical infrastructureCl. 25Up to 30–40 yrs + RM 2 million (loss of life)

How It Differs From the Computer Crimes Act 1997

To appreciate why this reform matters, it helps to remember the world the Computer Crimes Act 1997 was written for. In 1997, the internet in Malaysia was dial-up and dawning, e-commerce barely existed, smartphones were a decade away, and "AI" was science fiction. The Act was a genuinely forward-thinking piece of law for its time — one of the earliest computer crime statutes in the region — but it was built around a simple picture of wrongdoing: someone getting into a computer they shouldn't, and tampering with what they found. For nearly thirty years, prosecutors have had to stretch that compact framework over crimes its drafters could never have imagined, from ransomware syndicates to AI-generated deepfakes.

The 2026 Bill keeps the same underlying purpose but rebuilds the framework for the world we actually live in now. The table below sets the two side by side; the explanation that follows unpacks what each shift really means.

DimensionComputer Crimes Act 1997Cybercrimes Bill 2026
StructureSingle short Act, 5 principal offences8 Parts, 61 Clauses
GovernanceNo standing bodyCommittee on Combating Cybercrimes; NACSA integrated information system
Core focusUnauthorised access, modification, access-code misuseAbove, plus identity theft, deepfakes, intimate images, digital-ID misuse, online fraud
AI & synthetic mediaNot addressedExpress offences for AI-generated and manipulated content
Service providersNo specific dutiesPrevention duties, data retention, real-time traffic and content interception
Max standard penaltyRM 150,000 / 10 years (s.4)RM 1 million / 10 years (fraud); up to 40 years for CII offences
International alignmentPre-dates modern conventionsBudapest Convention & UN Convention Against Cybercrime

From five offences to a full framework

The most obvious change is sheer scope. The 1997 Act was a lean statute built around a handful of core offences. The 2026 Bill is a comprehensive framework of eight Parts and 61 clauses that not only defines a far wider range of offences, but also sets out how they are investigated, who coordinates the national response, and what duties fall on the companies that carry our data. It is the difference between a single rule and an entire operating system for tackling cybercrime.

Someone is now in charge

Under the old Act, there was no standing body responsible for the big picture — enforcement happened case by case, agency by agency. The new Bill creates the Committee on Combating Cybercrimes to set national strategy, coordinate the many agencies involved, and spot gaps before they are exploited, backed by a NACSA-run intelligence system that pools information across government. In practice, that means cybercrime is treated as a coordinated national problem rather than a series of isolated police reports.

The law finally names modern crimes

This is where the gap was widest. Identity theft, online fraud syndicates, the non-consensual sharing of intimate images, misuse of digital identity — none of these had a clean home in the 1997 Act, so prosecutors improvised, borrowing provisions written for other purposes. The Bill names these harms directly and gives each its own offence, which makes cases easier to bring and outcomes more predictable. And on AI and synthetic media, the contrast is absolute: the old Act said nothing, because in 1997 there was nothing to say; the new Bill creates express offences for deepfakes and manipulated content, putting Malaysia's law on the same footing as the technology it now has to police.

Duties for the companies that carry our data

The 1997 Act imposed no specific obligations on internet and telecommunications providers. The new Bill does — a general duty to take steps against their services being used for crime, alongside powers to require data preservation, disclosure, and in defined circumstances real-time interception. This is one of the more debated shifts, precisely because it draws service providers into the enforcement effort; the Bill balances it with a good-faith safe harbour and procedural safeguards, and it is explored further in the enforcement section below.

Heavier penalties, and an international backbone

The numbers tell their own story. The 1997 Act's principal penalties topped out around RM150,000; the new Bill's computer-related fraud offence reaches RM1 million and ten years, and offences striking critical national infrastructure can carry up to forty years. That escalation reflects how much more damage a cybercrime can now do — to a person's savings, or to services an entire population relies on. Finally, where the 1997 Act simply pre-dated the modern treaties, the new Bill is deliberately aligned with the Budapest Convention and the UN Convention Against Cybercrime, which matters enormously for a crime that rarely respects borders: it lets Malaysian authorities cooperate and gather evidence across jurisdictions in a way the old law was never designed to support.

Enforcement & Service-Provider Duties

Part VII gives authorised officers — police, or public officers and MCMC officers authorised by the Minister — wide investigation powers, including search and seizure with and without warrant, forfeiture, and the power to compel attendance and examination of persons.

Several provisions place direct obligations on service providers (defined broadly, whether licensed under the Communications and Multimedia Act 1998 or not):

Non-compliance with several of these duties can attract fines up to RM 1 million, with daily continuing penalties, and in some cases imprisonment up to 10 years. A good-faith safe harbour protects providers acting under their prevention duty (Cl. 53).

Extraterritorial Reach & International Alignment

Clause 2 gives the Act effect outside as well as within Malaysia, regardless of the offender's nationality, where the computer system, program or data was in Malaysia or connected to a system in Malaysia at the material time — or where the person affected is a Malaysian citizen. This deliberately broad reach is designed to satisfy Malaysia's obligations under two key instruments, both named in the Bill's explanatory statement:

The Bill in Context

The Cybercrimes Bill 2026 does not stand alone. It joins a maturing body of Malaysian digital legislation that includes the Cyber Security Act 2024 (Act 854), which governs critical information infrastructure and licenses cybersecurity service providers; the Personal Data Protection Act 2010 as amended in 2024; and the long-standing Communications and Multimedia Act 1998. Clause 25 directly borrows the Cyber Security Act 2024's definition of critical information infrastructure, knitting the two statutes together.

In its public framing, the government has tied the Bill to the scale of the problem: online-fraud losses in Malaysia exceeded RM2.9 billion in a single year, up more than 86% year on year. For the framework this Bill replaces, see the Computer Crimes Act 1997 reference page.

How It Affects Everyday Malaysians

Most cyber law sounds abstract until it touches an ordinary day. The Bill's significance is that the conduct it targets — a scam call, a fake nude, a borrowed login, a cloned voice — is exactly the kind of thing Malaysians already encounter. The scenarios below show where the Bill would bite. They are illustrative, not legal advice, and reflect the Bill as tabled.

Banking & money

The "bank officer" who isn't

You get a call from someone who knows your name and the last four digits of your card, claiming to be from your bank's fraud team. They walk you through "securing" your account and, by the end, your savings are gone — moved through a chain of mule accounts.

Now (Act 563, 1997)
Charged awkwardly across the Penal Code and Computer Crimes Act; identity misuse and the syndicate structure don't map cleanly onto 1997-era offences.
Under the Bill
Computer-related fraud (Cl. 17, up to RM1m / 10 yrs) and identity theft (Cl. 22) are explicit offences, with extraterritorial reach over offshore call centres.
Teens, students & image abuse

A fake nude made with an app

A classmate takes an ordinary photo from someone's Instagram, runs it through a "nudify" app, and circulates the fake in a group chat to humiliate them. The image is entirely synthetic — but the damage is real.

Now (Act 563, 1997)
No provision squarely covers AI-fabricated sexual images; "it's not a real photo" was a genuine grey area.
Under the Bill
Clause 24's intimate image expressly includes AI-generated and deepfake content — fakes are treated the same as real recordings, with up to 7 years where intent is to humiliate.
Family & elderly relatives

Your mother gets a call in your voice

An elderly parent receives a panicked call that sounds exactly like their child — "Mum, I've had an accident, I need money now." The voice is cloned from a few seconds of audio scraped off social media.

Now (Act 563, 1997)
Voice cloning didn't exist in 1997; the deception is chased through general cheating provisions after the money is gone.
Under the Bill
Clause 23 targets manipulated audio resembling a real person, used to facilitate a crime — capturing the cloned voice itself.
Digital ID & logins

Lending your MyDigital ID "just this once"

A friend or a "part-time job" recruiter asks you to share your MyDigital ID login or an OTP to "verify an account." It feels harmless. In reality your verified identity is being used to open accounts used in fraud.

Now (Act 563, 1997)
Sharing credentials sat in a grey zone unless a downstream offence could be proven against you directly.
Under the Bill
Clause 19 makes disclosing your digital identity password a crime in its own right — and if you did it for gain, the law presumes you knew (up to RM100k / 3 yrs).
Online sellers & small business

Your business gets cloned to run a scam

Fraudsters copy your Shopee or Instagram storefront, lift your photos and reviews, and set up a near-identical page that takes deposits for goods that never ship. Your customers are cheated, and your name carries the blame.

Now (Act 563, 1997)
Action depends on platform takedowns and scattered provisions; the forgery-of-identity element is hard to pin down.
Under the Bill
Computer-related forgery (Cl. 16) and fraud (Cl. 17) provisions give a clearer basis to pursue impersonation of a business.
Anyone with an email account

A leaked password and a drained account

Your reused password surfaces in a data breach. Someone logs into your email, resets your other accounts, and quietly takes over your digital life.

Now (Act 563, 1997)
Covered in principle by unauthorised-access provisions, but framed around 1990s notions of "computers".
Under the Bill
Modernised unauthorised access (Cl. 10), interception (Cl. 12) and data interference (Cl. 13) are written around today's computer systems.

If It Happens to You

Whether or not the Bill is in force yet, scam and cybercrime victims in Malaysia can call the National Scam Response Centre (NSRC) on 997 — the sooner a transfer is reported, the better the chance of freezing the money. Keep screenshots, numbers, and transaction records; they are what investigators work from.

Frequently Asked Questions

Is the Cybercrimes Bill 2026 already law?

Not yet. The Dewan Rakyat passed the Bill on 1 July 2026, but it becomes law only after it also passes the Dewan Negara, receives Royal Assent, is gazetted, and is commenced by the Minister on an appointed date. Until then, the Computer Crimes Act 1997 remains in force.

What happens to the Computer Crimes Act 1997?

Clause 61 repeals it in full. Investigations, trials or proceedings begun under the 1997 Act before commencement continue as if it had not been repealed, and references to the old Act in other laws are read as references to this Act.

Does it criminalise deepfakes?

Yes. Clause 23 covers AI-generated or manipulated content used to facilitate a crime, and Clause 24's definition of an intimate image expressly includes AI-generated, deepfake and synthesised content — whether authentic, altered, or entirely computer-generated.

Who enforces the new law?

Authorised officers (police, and authorised public or MCMC officers) carry out investigations and enforcement. A Committee on Combating Cybercrimes sets national strategy, and the Chief Executive of NACSA runs an integrated cybercrime information system. Prosecutions require the written consent of the Public Prosecutor.

How does it relate to the Cyber Security Act 2024?

They are complementary. The Cyber Security Act 2024 (Act 854) protects critical information infrastructure and licenses cybersecurity service providers; the Cybercrimes Bill 2026 defines and prosecutes cybercrime offences — and borrows the 2024 Act's definition of critical infrastructure for its most serious offence (Cl. 25).

Where can I read or download the Bill?

The full text as tabled at first reading is available to download as a PDF from this page, and is also published on the Parliament portal (parlimen.gov.my). This is the version as introduced and may be amended; the final authoritative text will be the gazetted Act from the Attorney General's Chambers (agc.gov.my).