Overview
The Cybercrimes Bill 2026 comes at a crucial time, in a world full of deception and tricks — enhanced by AI and other technology. The bill repeals the outdated Computer Crimes Act 1997, which has been in force for more than 30 years and came about as a result of the MSC initiative by the Malaysian government. The new Cybercrimes Act 2026 will provide more complete protection against identity theft, deepfakes, online fraud, and scams.
The Cybercrimes Bill 2026 (Rang Undang-Undang Jenayah Siber 2026) was tabled for its first reading in the Dewan Rakyat on 22 June 2026 by Deputy Prime Minister Datuk Seri Dr Ahmad Zahid Hamidi. It represents the most substantial overhaul of Malaysia's cybercrime legislation since the Computer Crimes Act 1997 (Act 563) — the foundational statute it is designed to repeal and replace. Once enacted, its short title will be the Cybercrimes Act 2026.
The government's rationale, set out in the Bill's own explanatory statement, is that the reform is necessitated by the rapid advancement of digital technology, the borderless nature of cyberspace, and the increasing sophistication of cybercrime activities that threaten national security, the economy, public order and the safety of persons. Cybercrime today extends well beyond hacking to encompass identity theft, organised online fraud, ransomware, the exploitation of generative AI, and deepfake-enabled deception.
Put plainly: in the golden age of AI in 2026, digital technology is advancing at the speed of light — and the law has been racing to keep up. Forgery and deepfake tools that were once the domain of specialists are now in almost everyone's pocket. With just a few taps on a phone, anyone can generate a convincing fake document, a cloned voice, or a fabricated image. That is exactly the reality the Computer Crimes Act 1997 was never built for, and exactly the gap this Bill sets out to close.
Structurally, the Bill comprises eight Parts and 61 Clauses. It establishes a Committee on Combating Cybercrimes to coordinate national strategy, and the Chief Executive of the National Cyber Security Agency (NACSA) serves as the Committee's secretary and runs an integrated information system for cybercrime intelligence.
Update (1 July 2026): the Dewan Rakyat passed the Bill on a majority voice vote after a debate involving 48 government and opposition MPs. During the debate, members raised concerns about the breadth of investigators' powers to access data, privacy safeguards, and the need to define AI-generated content carefully so that satire, artistic work and political criticism are not caught. Winding up, Deputy Prime Minister Datuk Seri Dr Ahmad Zahid Hamidi stressed that the powers are not absolute — access to computer systems and data must follow prescribed legal procedures, and data disclosure requires a written notice tied to a lawful investigation. The Bill now proceeds to the Dewan Negara.
The Next Chapter of the MSC Malaysia Cyber Law Framework
The Computer Crimes Act 1997 was one of the five original cyber laws enacted under the MSC Malaysia Bill of Guarantees. Its replacement by the Cybercrimes Bill 2026 marks the next chapter of that framework — preserving Malaysia's long-standing commitment to legal certainty in the digital economy while modernising it for AI-era threats.
Important — Passed by the Dewan Rakyat, Not Yet in Force
This page is a public reference resource and does not constitute legal advice. On 1 July 2026 the Bill was passed by the Dewan Rakyat, but it is not yet law. It must still pass the Dewan Negara (Senate), receive Royal Assent, be gazetted, and be commenced by the Minister on a date appointed by notification in the Gazette. Its provisions may also be amended along the way. Until commencement, the Computer Crimes Act 1997 remains the law in force. For the authoritative text once enacted, refer to the Attorney General's Chambers of Malaysia, and consult a qualified Malaysian advocate and solicitor for any specific matter.
Legislative Status & Timeline
The Bill has moved quickly. It was passed by the Dewan Rakyat on 1 July 2026 following debate by 48 MPs, but under Clause 1 the Act comes into operation only on a date appointed by the Minister by notification in the Gazette — so passage in the lower house is not the same as the law taking effect. It must still clear the Dewan Negara, receive Royal Assent, and be gazetted and commenced. Until then, the Computer Crimes Act 1997 remains the operative law.
Key Offences Under the Bill
Here is where the Bill stops being abstract. Its offences live in Parts III to VI, and what strikes you reading them is how closely they map to the scams and harms Malaysians actually run into — the drained bank account, the fake nude, the borrowed login, the cloned voice on the phone. Below are the ones that matter most, with the penalties taken straight from the Bill as tabled.
One thread runs through nearly all of them, and it is worth holding onto as you read: an act only becomes an offence when it is done intentionally and without authority or without lawful purpose. In other words, the Bill is aimed at people who set out to deceive or harm — not at the researcher, the journalist, or the ordinary user who stumbles into something innocently. That intent requirement is the line between a crime and an accident, and it appears again and again below.
Access to a Computer System Without Authority
This is the foundation stone — the modern successor to the old Section 3 of the 1997 Act. It covers intentionally getting into any part of a computer system you have no authority or lawful reason to enter. Think of someone logging into an account that isn't theirs, or slipping past a login they were never meant to pass. It doesn't matter whether they were after any particular file or program; simply securing the access without permission is the offence. It's the entry point that so many bigger crimes start from, which is why the Bill treats plain unauthorised access as wrong in itself, before any further harm is even attempted.
Up to RM 100,000 or 3 years' imprisonment or bothUnauthorised Access With Intent to Commit a Further Offence
This is the same break-in, but with a darker purpose behind it. Where someone gains access not just to snoop, but as a stepping stone to something worse — fraud, dishonesty, or causing injury as defined in the Penal Code — the law comes down harder. The reasoning is intuitive: breaking into a system to steal money or hurt someone is far more serious than wandering in out of curiosity, so the penalty roughly doubles. It's the difference between trespassing and breaking in to commit a robbery.
Up to RM 500,000 or 7 years' imprisonment or bothInterception, Data & System Interference, Misuse of Device
This cluster covers the classic toolkit of hacking. Interception (Cl. 12) is the digital equivalent of wiretapping — secretly capturing data as it travels to, from or within a system. Data interference (Cl. 13) is tampering with the information itself: deleting, corrupting or locking files, which is exactly what a ransomware attack does. System interference (Cl. 14) goes after the machine's ability to function at all — think of an attack that knocks a service offline. And misuse of device (Cl. 15) reaches back a step further, to the people who make, sell or stockpile the hacking tools, stolen passwords and access credentials that the other offences rely on. By criminalising the supply chain, the Bill tries to choke off attacks before they happen.
Up to RM 500,000 / 7 years (interception, system interference, misuse) · RM 100,000 / 3 years (data interference) · possession: RM 300,000 / 5 yearsComputer-Related Forgery
Forgery is an old crime that has simply moved online. Instead of faking a signature on paper, someone alters or fabricates computer data so that false information passes as genuine — a doctored contract, a tampered record, a fake certificate meant to be relied on for a legal purpose. The penalty steps up when a "valuable security" is involved, meaning a document that creates or transfers real legal rights, because the potential for harm is that much greater. It's the digital version of putting your name on something that was never truly yours to sign.
RM 500,000 / 7 years (valuable security) · RM 300,000 / 5 years (other cases)Computer-Related Fraud
If any single clause is aimed at the scam epidemic, it's this one — and the penalty, the heaviest of the standard offences, tells you how seriously the government takes it. It covers manipulating data or a system, or deceiving someone through a computer, in order to cause them financial loss while dishonestly enriching yourself or another. This is the legal net cast over the investment scams, fake job offers, phishing operations and mule-account rackets that have cost Malaysians billions. Where the old law strained to fit these schemes into decades-old wording, this clause names the harm directly: online deception for profit.
Up to RM 1 million or 10 years' imprisonment or bothDisclosing a National Digital Identity Password
As Malaysia moves toward a national digital identity, your MyDigital ID becomes a master key to a great deal of your life — which is exactly why handing it over is now its own offence. If a registered user gives away their digital identity password, or otherwise lets someone act in their identity, knowing (or having good reason to suspect) it will be used for a crime, they're on the hook. There's a sting in the tail worth noting: if you did it for gain, the law presumes you knew what it would be used for, and it's on you to prove otherwise. The message is blunt — your digital identity is not something to lend out, not even "just this once."
Up to RM 100,000 or 3 years' imprisonment or bothObtaining or Supplying a User Credential
Where the previous clause targets the person who gives their own identity away, this one goes after the trade in other people's. Obtaining, keeping, supplying or passing around someone's digital-identity credentials — including biometric data and digital certificates — for use in a crime is an offence, and a repeat offence carries a heavier penalty. This is aimed squarely at the market that fuels identity fraud: the sellers and brokers of stolen credentials who never commit the final scam themselves but make it possible.
RM 100,000 / 3 years · second offence: RM 300,000 / 5 yearsIdentity Theft
Your identity is now one of your most valuable — and most stolen — possessions. This clause makes it an offence to use a computer to obtain, supply, use or even just hold someone else's identity information with the intent to commit or facilitate a crime. The definition of "identity information" is deliberately wide: anything that identifies, or even purports to identify, a person. That breadth matters, because identity thieves are endlessly inventive, and a narrow definition would leave gaps for them to slip through. It's a direct answer to the mule-account recruiters and impersonation syndicates that have become so common.
Up to RM 500,000 or 7 years' imprisonment or bothSynthetic & Manipulated Content (Deepfakes)
This is one of the most forward-looking parts of the whole Bill, and the reason it feels so timely. It targets AI-generated or manipulated audio and video — content made to resemble a real person, place, object or event, and passed off as authentic to help commit a crime. The scam call in a loved one's cloned voice, the fake video of a public figure "endorsing" an investment, the doctored clip used to trick a victim into paying: these are the harms it's built for. Crucially, it's not the technology that's criminalised — using AI is not itself an offence — but the deceptive, harmful use of it. Intent and purpose are still what turn a clever fake into a crime.
Up to RM 500,000 or 7 years' imprisonment or bothDissemination of Intimate Images
This clause confronts one of the cruelest abuses of the AI era. It's an offence to share, publish or sell a person's intimate image through a computer system — and, importantly, the Bill's own explanatory statement makes clear that an "intimate image" includes content that is AI-generated, deepfaked or synthesised. In other words, the old defence of "but it isn't really her, I made it" no longer holds: a fabricated nude is treated the same as a genuine one, because the humiliation and harm to the victim are just as real. The penalty rises sharply when the aim is to humiliate, harm, coerce or intimidate the person depicted — recognising that this is often less about images than about power and cruelty.
Base: RM 300,000 / 5 years · Aggravated: RM 500,000 / 7 yearsOffences Affecting Critical Information Infrastructure
Some targets are simply too important to treat like any other. When one of these offences strikes national critical information infrastructure — the systems behind power, water, banking, healthcare, telecommunications, as defined in the Cyber Security Act 2024 — the penalties become the most severe in the entire Bill. The reason is sobering: an attack on these systems can ripple out into the physical world, disrupting essential services and even endangering lives. That's why the law reserves its harshest response, up to forty years' imprisonment where loss of life results, for those who would turn a cyberattack into a threat against the nation itself.
Loss of life: 30–40 years + up to RM 2 million · Injury: up to 15 years + RM 1.5 million · Otherwise: RM 1 million / 10 yearsStructure — The Eight Parts
The Bill is organised into eight Parts spanning 61 Clauses, set out in its arrangement of clauses as follows.
| Part | Coverage |
|---|---|
| Part I | Preliminary — short title and commencement, extra-territorial application, and definitions (Clauses 1–3). |
| Part II | Committee on Combating Cybercrimes — establishment, membership, functions, meetings and subcommittees (Clauses 4–8). |
| Part III | Offences relating to the confidentiality, integrity and availability of computer systems and data — access, interception, data and system interference, misuse of device (Clauses 9–15). |
| Part IV | Computer-related forgery and computer-related fraud (Clauses 16–17). |
| Part V | Offences relating to the National Digital Identity Service — disclosure of passwords and credential offences (Clauses 18–20). |
| Part VI | Other offences — wrongful communication, identity theft, synthetic/manipulated content, intimate images, and critical-infrastructure aggravation (Clauses 21–25). |
| Part VII | Enforcement — authorisation of officers, investigation, search and seizure, data preservation and disclosure, real-time traffic collection and interception, jurisdiction (Clauses 26–49). |
| Part VIII | Miscellaneous — integrated information system, service-provider duties, data retention, court orders, liability, and the repeal of the 1997 Act (Clauses 50–61). |
The Committee on Combating Cybercrimes
A genuinely new feature of the Bill, absent from the 1997 Act, is a high-level coordinating body. Part II establishes the Committee on Combating Cybercrimes, chaired by the Chief Secretary to the Government with the Director General of National Security as deputy. Its membership spans the Attorney General, the Inspector-General of Police, Bank Negara, the Securities Commission, the Companies Commission, the Personal Data Protection Commissioner, the National Anti-Financial Crime Centre, and the MCMC, among others.
The Committee's role is strategic rather than prosecutorial: to plan and decide national approaches to preventing and combating cybercrime, advise the Government on policy, coordinate enforcement agencies, assess the effectiveness of existing mechanisms, and identify gaps in the legal framework. The Chief Executive of NACSA serves as its secretary.
Penalties at a Glance
Penalties scale with the seriousness of the conduct. The figures below are drawn directly from the Bill as tabled and are subject to amendment in debate.
| Offence | Clause | Maximum penalty |
|---|---|---|
| Access to a computer system without authority | Cl. 10 | RM 100,000 / 3 years |
| Access with intent to commit further offence | Cl. 11 | RM 500,000 / 7 years |
| Interception without authority | Cl. 12 | RM 500,000 / 7 years |
| Computer data interference | Cl. 13 | RM 100,000 / 3 years |
| Computer system interference | Cl. 14 | RM 500,000 / 7 years |
| Misuse of device (making available) | Cl. 15(1) | RM 500,000 / 7 years |
| Computer-related forgery | Cl. 16 | RM 500,000 / 7 yrs (valuable security); RM 300,000 / 5 yrs (other) |
| Computer-related fraud | Cl. 17 | RM 1 million / 10 years |
| Disclosing a digital identity password | Cl. 19 | RM 100,000 / 3 years |
| Wrongful communication of access | Cl. 21 | RM 300,000 / 5 years |
| Identity theft | Cl. 22 | RM 500,000 / 7 years |
| Synthetic / manipulated content (deepfakes) | Cl. 23 | RM 500,000 / 7 years |
| Dissemination of intimate images | Cl. 24 | RM 300,000 / 5 yrs base; RM 500,000 / 7 yrs aggravated |
| Offence affecting critical infrastructure | Cl. 25 | Up to 30–40 yrs + RM 2 million (loss of life) |
How It Differs From the Computer Crimes Act 1997
To appreciate why this reform matters, it helps to remember the world the Computer Crimes Act 1997 was written for. In 1997, the internet in Malaysia was dial-up and dawning, e-commerce barely existed, smartphones were a decade away, and "AI" was science fiction. The Act was a genuinely forward-thinking piece of law for its time — one of the earliest computer crime statutes in the region — but it was built around a simple picture of wrongdoing: someone getting into a computer they shouldn't, and tampering with what they found. For nearly thirty years, prosecutors have had to stretch that compact framework over crimes its drafters could never have imagined, from ransomware syndicates to AI-generated deepfakes.
The 2026 Bill keeps the same underlying purpose but rebuilds the framework for the world we actually live in now. The table below sets the two side by side; the explanation that follows unpacks what each shift really means.
| Dimension | Computer Crimes Act 1997 | Cybercrimes Bill 2026 |
|---|---|---|
| Structure | Single short Act, 5 principal offences | 8 Parts, 61 Clauses |
| Governance | No standing body | Committee on Combating Cybercrimes; NACSA integrated information system |
| Core focus | Unauthorised access, modification, access-code misuse | Above, plus identity theft, deepfakes, intimate images, digital-ID misuse, online fraud |
| AI & synthetic media | Not addressed | Express offences for AI-generated and manipulated content |
| Service providers | No specific duties | Prevention duties, data retention, real-time traffic and content interception |
| Max standard penalty | RM 150,000 / 10 years (s.4) | RM 1 million / 10 years (fraud); up to 40 years for CII offences |
| International alignment | Pre-dates modern conventions | Budapest Convention & UN Convention Against Cybercrime |
From five offences to a full framework
The most obvious change is sheer scope. The 1997 Act was a lean statute built around a handful of core offences. The 2026 Bill is a comprehensive framework of eight Parts and 61 clauses that not only defines a far wider range of offences, but also sets out how they are investigated, who coordinates the national response, and what duties fall on the companies that carry our data. It is the difference between a single rule and an entire operating system for tackling cybercrime.
Someone is now in charge
Under the old Act, there was no standing body responsible for the big picture — enforcement happened case by case, agency by agency. The new Bill creates the Committee on Combating Cybercrimes to set national strategy, coordinate the many agencies involved, and spot gaps before they are exploited, backed by a NACSA-run intelligence system that pools information across government. In practice, that means cybercrime is treated as a coordinated national problem rather than a series of isolated police reports.
The law finally names modern crimes
This is where the gap was widest. Identity theft, online fraud syndicates, the non-consensual sharing of intimate images, misuse of digital identity — none of these had a clean home in the 1997 Act, so prosecutors improvised, borrowing provisions written for other purposes. The Bill names these harms directly and gives each its own offence, which makes cases easier to bring and outcomes more predictable. And on AI and synthetic media, the contrast is absolute: the old Act said nothing, because in 1997 there was nothing to say; the new Bill creates express offences for deepfakes and manipulated content, putting Malaysia's law on the same footing as the technology it now has to police.
Duties for the companies that carry our data
The 1997 Act imposed no specific obligations on internet and telecommunications providers. The new Bill does — a general duty to take steps against their services being used for crime, alongside powers to require data preservation, disclosure, and in defined circumstances real-time interception. This is one of the more debated shifts, precisely because it draws service providers into the enforcement effort; the Bill balances it with a good-faith safe harbour and procedural safeguards, and it is explored further in the enforcement section below.
Heavier penalties, and an international backbone
The numbers tell their own story. The 1997 Act's principal penalties topped out around RM150,000; the new Bill's computer-related fraud offence reaches RM1 million and ten years, and offences striking critical national infrastructure can carry up to forty years. That escalation reflects how much more damage a cybercrime can now do — to a person's savings, or to services an entire population relies on. Finally, where the 1997 Act simply pre-dated the modern treaties, the new Bill is deliberately aligned with the Budapest Convention and the UN Convention Against Cybercrime, which matters enormously for a crime that rarely respects borders: it lets Malaysian authorities cooperate and gather evidence across jurisdictions in a way the old law was never designed to support.
Enforcement & Service-Provider Duties
Part VII gives authorised officers — police, or public officers and MCMC officers authorised by the Minister — wide investigation powers, including search and seizure with and without warrant, forfeiture, and the power to compel attendance and examination of persons.
Several provisions place direct obligations on service providers (defined broadly, whether licensed under the Communications and Multimedia Act 1998 or not):
- Expedited preservation of computer data on written notice where it is at risk of being destroyed (Cl. 38).
- Disclosure of specified computer data on written notice (Cl. 39).
- Real-time collection of traffic data and interception of content data, on the authority of the Public Prosecutor (Cl. 40–41).
- A general duty to take measures to prevent their services being used for cybercrime (Cl. 51), and a power for the Minister to order retention of computer data in the interest of national security or public safety (Cl. 52).
Non-compliance with several of these duties can attract fines up to RM 1 million, with daily continuing penalties, and in some cases imprisonment up to 10 years. A good-faith safe harbour protects providers acting under their prevention duty (Cl. 53).
Extraterritorial Reach & International Alignment
Clause 2 gives the Act effect outside as well as within Malaysia, regardless of the offender's nationality, where the computer system, program or data was in Malaysia or connected to a system in Malaysia at the material time — or where the person affected is a Malaysian citizen. This deliberately broad reach is designed to satisfy Malaysia's obligations under two key instruments, both named in the Bill's explanatory statement:
- The Budapest Convention on Cybercrime (Council of Europe) — the leading treaty on harmonising cybercrime law and cross-border evidence gathering.
- The United Nations Convention Against Cybercrime — a newer global instrument Malaysia positioned itself as an early signatory to, with NACSA as lead coordinating agency.
The Bill in Context
The Cybercrimes Bill 2026 does not stand alone. It joins a maturing body of Malaysian digital legislation that includes the Cyber Security Act 2024 (Act 854), which governs critical information infrastructure and licenses cybersecurity service providers; the Personal Data Protection Act 2010 as amended in 2024; and the long-standing Communications and Multimedia Act 1998. Clause 25 directly borrows the Cyber Security Act 2024's definition of critical information infrastructure, knitting the two statutes together.
In its public framing, the government has tied the Bill to the scale of the problem: online-fraud losses in Malaysia exceeded RM2.9 billion in a single year, up more than 86% year on year. For the framework this Bill replaces, see the Computer Crimes Act 1997 reference page.
How It Affects Everyday Malaysians
Most cyber law sounds abstract until it touches an ordinary day. The Bill's significance is that the conduct it targets — a scam call, a fake nude, a borrowed login, a cloned voice — is exactly the kind of thing Malaysians already encounter. The scenarios below show where the Bill would bite. They are illustrative, not legal advice, and reflect the Bill as tabled.
The "bank officer" who isn't
You get a call from someone who knows your name and the last four digits of your card, claiming to be from your bank's fraud team. They walk you through "securing" your account and, by the end, your savings are gone — moved through a chain of mule accounts.
A fake nude made with an app
A classmate takes an ordinary photo from someone's Instagram, runs it through a "nudify" app, and circulates the fake in a group chat to humiliate them. The image is entirely synthetic — but the damage is real.
Your mother gets a call in your voice
An elderly parent receives a panicked call that sounds exactly like their child — "Mum, I've had an accident, I need money now." The voice is cloned from a few seconds of audio scraped off social media.
Lending your MyDigital ID "just this once"
A friend or a "part-time job" recruiter asks you to share your MyDigital ID login or an OTP to "verify an account." It feels harmless. In reality your verified identity is being used to open accounts used in fraud.
Your business gets cloned to run a scam
Fraudsters copy your Shopee or Instagram storefront, lift your photos and reviews, and set up a near-identical page that takes deposits for goods that never ship. Your customers are cheated, and your name carries the blame.
A leaked password and a drained account
Your reused password surfaces in a data breach. Someone logs into your email, resets your other accounts, and quietly takes over your digital life.
If It Happens to You
Whether or not the Bill is in force yet, scam and cybercrime victims in Malaysia can call the National Scam Response Centre (NSRC) on 997 — the sooner a transfer is reported, the better the chance of freezing the money. Keep screenshots, numbers, and transaction records; they are what investigators work from.
Frequently Asked Questions
Is the Cybercrimes Bill 2026 already law?
Not yet. The Dewan Rakyat passed the Bill on 1 July 2026, but it becomes law only after it also passes the Dewan Negara, receives Royal Assent, is gazetted, and is commenced by the Minister on an appointed date. Until then, the Computer Crimes Act 1997 remains in force.
What happens to the Computer Crimes Act 1997?
Clause 61 repeals it in full. Investigations, trials or proceedings begun under the 1997 Act before commencement continue as if it had not been repealed, and references to the old Act in other laws are read as references to this Act.
Does it criminalise deepfakes?
Yes. Clause 23 covers AI-generated or manipulated content used to facilitate a crime, and Clause 24's definition of an intimate image expressly includes AI-generated, deepfake and synthesised content — whether authentic, altered, or entirely computer-generated.
Who enforces the new law?
Authorised officers (police, and authorised public or MCMC officers) carry out investigations and enforcement. A Committee on Combating Cybercrimes sets national strategy, and the Chief Executive of NACSA runs an integrated cybercrime information system. Prosecutions require the written consent of the Public Prosecutor.
How does it relate to the Cyber Security Act 2024?
They are complementary. The Cyber Security Act 2024 (Act 854) protects critical information infrastructure and licenses cybersecurity service providers; the Cybercrimes Bill 2026 defines and prosecutes cybercrime offences — and borrows the 2024 Act's definition of critical infrastructure for its most serious offence (Cl. 25).
Where can I read or download the Bill?
The full text as tabled at first reading is available to download as a PDF from this page, and is also published on the Parliament portal (parlimen.gov.my). This is the version as introduced and may be amended; the final authoritative text will be the gazetted Act from the Attorney General's Chambers (agc.gov.my).