search

LEMON BLOG

Malaysia Moves to Replace Its 1997 Computer Crime Law With a Broader Cybercrimes Framework

Malaysia is preparing for one of its most significant updates to cybercrime legislation in nearly three decades. The Cybercrimes Bill 2026 has cleared both chambers of Parliament, passing the Dewan Rakyat on July 1 and the Dewan Negara on July 20. The proposed law is designed to repeal the Computer Crimes Act 1997 and replace it with a broader framework covering modern offences such as digital fraud, identity abuse, ransomware, deepfakes and the criminal misuse of artificial intelligence. 

Official parliamentary records currently list the Bill as passed. Its practical effect will depend on the remaining legal formalities, including gazettement and the date on which its provisions are brought into force.

Why a Law Written in 1997 Is No Longer Enough

When the Computer Crimes Act was introduced in 1997, online threats looked very different.

The law was largely built around offences such as unauthorised access, password misuse and interference with computer systems. It emerged before smartphones, social media, cloud computing, generative AI, cryptocurrency and today's highly organised online scam networks became part of everyday life.

Modern cybercrime is rarely limited to someone simply "hacking into a computer."

A single operation may now involve stolen identities, impersonation through deepfake video, fraudulent bank transfers, compromised messaging accounts, cloud-hosted malware, cross-border money mules and personal information obtained from several different platforms.

The Cybercrimes Bill attempts to address that wider environment through eight parts and 61 clauses, using what the government describes as a technology-neutral approach. Instead of writing offences around one specific product or platform, the framework is intended to remain applicable as technologies continue evolving.

The Law Targets Criminal Use of AI, Not AI Itself

One of the most important clarifications made during the parliamentary debates was that the Bill does not make the use of artificial intelligence an offence by itself.

AI-generated content would not automatically become illegal merely because software was used to produce it. Prosecutors would still need to demonstrate relevant elements such as criminal intention, the purpose for which the technology was used and the harm or effect resulting from the act.

The distinction matters because the same technology can be used for both legitimate and harmful purposes.

Generative AI can assist with education, research, accessibility and creative work. The same tools can also be misused to impersonate public figures, fabricate evidence, manipulate elections, conduct fraud or create exploitative material.

The proposed legislation is therefore aimed at the conduct and intended criminal outcome, rather than banning a particular technology.

Deputy Rural and Regional Development Minister Rubiah Wang told the Dewan Negara that examples of criminal misuse could include fraud, election interference and sexual exploitation. She also stressed that lawful journalism, academic inquiry and expression conducted within the law were not the intended targets of the Bill.

Deepfakes Are No Longer Just a Reputation Problem

Deepfake technology has moved beyond edited celebrity videos and online jokes.

A convincing artificial voice or video can be used to impersonate a company director, family member, political candidate or senior government official. Criminals can combine the content with stolen personal information to make a fraudulent request appear authentic.

The Bill includes offences connected to deepfakes and digitally manipulated intimate images. These provisions are intended to provide clearer legal protection for victims, particularly women, children, older people and others who may be targeted through exploitation, extortion or non-consensual content.

For victims, the harm often continues long after the original content is uploaded.

Copies can be downloaded, reposted and distributed across multiple platforms. Removing one post does not necessarily stop the material from circulating elsewhere.

This is why enforcement cooperation with digital platforms is likely to become just as important as prosecution. The government has said it intends to work with the Malaysian Communications and Multimedia Commission, platform operators and international partners to accelerate the removal of unlawful content.

Victims Need More Than a Criminal Conviction

A prison sentence may punish an offender, but it does not automatically restore money, accounts or digital identities that have been stolen.

During the Dewan Negara debate, senators called for stronger victim-focused measures, including compensation, faster removal of harmful content and remedies for compromised online identities.

The Bill also includes a restitution mechanism. Reporting on the Senate debate indicated that Clause 54 would allow courts to make restitution-related orders and restrict property in order to protect victims and preserve assets connected to an offence.

This is especially relevant in online fraud cases.

Scam victims may lose their life savings within minutes, while the money is rapidly transferred through multiple bank accounts, e-wallets or overseas channels. By the time the investigation identifies the perpetrators, the funds may already be difficult to recover.

A stronger legal framework therefore needs to support not only prosecution but also faster account freezing, asset tracing, content removal and victim recovery.

Banks and Telcos Are Part of the Security Chain

Cybercrime laws can punish criminals, but prevention also depends heavily on the systems operated by banks, telecommunications companies and digital platforms.

Senators urged financial institutions and telcos to reduce their dependence on SMS one-time passwords and move towards stronger authentication.

SMS verification has long been widely used because it is simple and familiar. However, it can be weakened through SIM-swap fraud, phishing, malicious mobile applications and social engineering.

More secure options may include authenticator applications, passkeys, hardware-backed authentication, device binding and transaction confirmation that clearly displays the recipient and amount before approval.

The parliamentary suggestion does not mean every SMS OTP will immediately disappear. It reflects a growing recognition that authentication controls must evolve alongside scam tactics.

Financial institutions also need systems capable of identifying unusual transfers, new devices, rapid changes to account settings and suspicious payment patterns before the money leaves the financial system.

Cybercrime Rarely Stops at Malaysia's Borders

Online criminals do not need to be physically located in the country where their victims live.

The attacker may operate from one jurisdiction, host infrastructure in another, use financial accounts in several countries and communicate through platforms headquartered elsewhere.

That makes cross-border cooperation essential.

Rubiah said offences under the proposed law would qualify as extraditable because they carry potential prison terms of at least three years. Under Malaysia's extradition framework, offences punishable with imprisonment of one year or more may meet the required threshold.

Authorities are expected to rely on mechanisms such as mutual legal assistance, Interpol, Aseanapol and direct cooperation between police agencies.

The Mutual Assistance in Criminal Matters Act 2002 may also be used to obtain overseas evidence, testimony, search assistance and information needed to identify or locate suspects.

This does not mean every overseas scammer can be brought back easily.

Success will still depend on cooperation from the country involved, the availability of evidence, applicable treaties and differences between national laws. However, defining serious offences clearly can give investigators a stronger basis for making formal international requests.

Malaysia Is Aligning With International Cybercrime Standards

The new framework is also connected to Malaysia's international commitments.

The government has said the Bill is intended to help the country meet obligations associated with the Budapest Convention on Cybercrime and the United Nations Convention against Cybercrime.

International alignment can make it easier for enforcement agencies to cooperate on digital evidence, preserve data and coordinate investigations involving multiple jurisdictions.

Digital evidence can disappear quickly.

A platform may retain account logs only for a limited period. An attacker may delete a cloud server, abandon an email account or transfer funds again before authorities complete the normal request process.

Cybercrime investigations therefore require mechanisms for rapid data preservation while formal legal procedures continue.

Who Will Investigate and Coordinate Cases?

The Royal Malaysia Police is expected to remain the primary agency responsible for investigating criminal offences under the framework, with the Commercial Crime Investigation Department playing a leading role in fraud-related cases.

The National Cyber Security Agency would serve as a strategic coordinator alongside the Malaysian Communications and Multimedia Commission, Bank Negara Malaysia and other relevant technical bodies.

This division is important because cybercrime is rarely handled effectively by one organisation.

Police may investigate the offender, while a bank traces payments, a telecommunications company preserves subscriber data, MCMC engages a platform and cybersecurity specialists analyse compromised devices.

Without clear coordination, critical evidence may remain spread across different organisations and response times may be slower.

Malaysia has also established a Cybersecurity and Cryptology Development Centre by combining CyberSecurity Malaysia and the Malaysian Cryptology Technology and Management Centre under NACSA. The initiative is intended to strengthen specialist capabilities, including AI-related digital forensics.

Investigative Powers Must Come With Safeguards

Stronger cybercrime enforcement inevitably raises questions about privacy, device seizure and access to personal information.

Investigators may need to examine computers, communication records, cloud accounts and stored data. Those powers can be necessary for legitimate investigations, but they must not become open-ended.

The government has said the Bill does not provide authorities with absolute power.

Access to computer systems, data preservation and disclosure would remain subject to legal procedures and written notices. The stated intention is to balance effective enforcement with fundamental rights and privacy protections.

Members of Parliament also raised concerns about data-access powers, the seizure of electronic devices and the need for clear definitions surrounding AI-generated material.

These concerns are important because ambiguous language could create uncertainty for researchers, journalists, cybersecurity professionals and ordinary users conducting legitimate activities.

The effectiveness of the legislation will therefore depend not only on what the clauses say, but also on how investigators, prosecutors and courts interpret and apply them.

Cybersecurity Researchers Need Legal Certainty

Security researchers sometimes access or test systems to identify vulnerabilities. Responsible research can help organisations fix weaknesses before criminals exploit them.

However, the line between authorised testing and illegal access must remain clear.

Researchers need documented permission, defined testing scopes and proper vulnerability-disclosure procedures. Organisations should also establish channels through which security weaknesses can be reported safely.

A modern cybercrime law should punish genuinely malicious activity without discouraging good-faith research that improves public security.

The same principle applies to academic analysis, journalism and public-interest reporting. Legitimate investigation and commentary should not be treated in the same way as fraud, exploitation or deliberate interference with computer systems.

Scam Prevention Still Requires Public Awareness

Legislation alone cannot eliminate cybercrime.

The government noted that police-recorded cybercrime cases rose from 25,479 in 2022 to 66,204 in 2025, illustrating the scale and speed at which the problem has grown.

Many incidents begin not with an advanced technical exploit, but with social engineering.

A victim may be persuaded to reveal a password, install a remote-access application, approve a transaction or believe an impersonated authority figure.

This means legal reform must be supported by digital literacy, stronger organisational procedures and better security controls.

People should be encouraged to verify urgent payment requests through a separate channel, avoid installing applications at the direction of unknown callers and treat unexpected requests for credentials or transaction approvals with suspicion.

Businesses should also prepare formal procedures for reporting suspected fraud quickly, because the chances of recovering money often decrease as time passes.

What the Bill Means for Organisations

Companies should not view the Cybercrimes Bill only as something directed at criminals.

The broader enforcement environment may affect how organisations preserve logs, respond to lawful requests, report incidents and protect customer information.

Banks, telcos, digital platforms and organisations managing sensitive systems may face greater expectations around cooperation, data preservation and incident response.

Businesses should review:

Cybercrime legislation may create a stronger enforcement foundation, but organisations still need their own technical and procedural defences.

Final Thoughts

The Cybercrimes Bill 2026 represents a major attempt to modernise Malaysia's response to an online threat landscape that has changed dramatically since 1997.

Its importance lies not simply in introducing heavier penalties. The proposed framework recognises that cybercrime now includes AI-enabled fraud, digital impersonation, exploitative content, identity abuse and organised operations that cross national borders.

The Bill also moves the conversation closer to victim recovery, international cooperation and clearer coordination between enforcement, financial, communications and cybersecurity agencies.

However, strong laws must be matched by strong safeguards.

Investigative powers should remain accountable, lawful expression must be protected and legitimate security research should not be discouraged. Courts and enforcement agencies will also need sufficient technical expertise to apply the provisions fairly.

Malaysia is moving toward a more modern cybercrime framework. The real test will come after implementation—when authorities must demonstrate that it can protect victims, support effective investigations and keep pace with technology without unnecessarily limiting legitimate digital activity.

Google Enlists Malaysian YouTube Creators to Promo...
Chaos Ransomware Turns Chrome and Edge Into Covert...

Related Posts

 

Comments

No comments made yet. Be the first to submit a comment
Monday, 27 July 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection