Cybercrimes Bill 2026: Key Legal Concepts and Their Implications

Introduction

Cybercrimes Bill 2026 (“the Bill”) represents an important attempt to bring Malaysia’s cybercrime laws into the digital age and will replace the existing Computer Crimes Act 1997 (“CCA 1997”). The Bill is a comprehensive framework proposed to address increasingly complex cyber threats, bridging the gaps in the existing legal landscape and ensuring that domestic law remains relevant as technology evolves.

The Bill was passed by the Dewan Rakyat on 1 July 2026 and subsequently by the Dewan Negara on 20 July 2026 and currently waiting for Royal Assent before it becomes law and will come into operation on a date to be determined by the Minister (in charge with responsibility for matters relating to cybercrimes) by notification in the Gazette.

 

What makes the Bill different from the traditional concept of “computer crime”?

Traditionally, the concept of computer crime has been associated primarily with offences directed at a computer system itself, such as unauthorised access or interference with computer data.

The Bill adopts a broader approach by addressing not only offences where the computer system or computer data is the target of criminal conduct, but also offences where technology is used as a means or instrument to facilitate other criminal conduct. The distinction between the two (2) may broadly be understood through the concepts of cyber-dependent and cyber-enabled offence.

Cyber-dependent offences are offences that depend on information and communications technology and could not ordinarily be committed without a computer system or network. The relevant provisions under the Bill include the following:

In the above-mentioned circumstances, the computer system or computer data itself is central to the offending conduct.

By contrast, cyber-enabled offences involve conduct where technology facilitates, enhances or provides the means for committing an offence that could potentially exist outside the digital environment. The relevant provisions under the Bill include the following:

 

How does the Bill address online fraud and social engineering?

Section 17 of the Bill introduces an offence of computer-related fraud, representing a significant development in Malaysia’s legal framework for addressing fraud committed through digital means. This provision is particularly relevant to the current environment of phishing, online scams and social engineering. A cybercriminal may not need to break into a banking system if the victim can instead be persuaded to disclose credentials or transfer money.

This provision therefore potentially gives the law greater relevance to modern cyber-enabled fraud. At the same time, its application will depend on how concepts such as intention, deception, causation and economic benefit are interpreted and established in individual cases.

 

Does the Bill address AI-generated content and deepfakes?

Section 23 of the Bill addresses the use of computer-generated or manipulated visual and audio content that falsely appears to be authentic or truthful, including content resembling an existing person, object, place, entity or event. The provision is sufficiently broad to address forms of deceptive synthetic content, including:

  • deepfakes;
  • voice cloning;
  • AI-generated impersonation; and/or
  • synthetic media used for fraudulent purposes.

This provision does not appear to criminalise the creation or dissemination of such content merely because it is AI-generated or manipulated. The relevant conduct must be carried out with the intention of committing or facilitating the commission of an offence under any written law.

 

Can the Bill apply to cybercrime committed outside Malaysia?

Yes. Section 2 of the Bill provides for extra-territorial application of the Bill, regardless of the nationality or citizenship of the person who commits the offence. Further, an offence committed outside Malaysia may be dealt with as if it had been committed in Malaysia where:

  • the relevant computer system, program or computer data is in Malaysia at the material time;
  • the relevant system, program or computer data is connected to Malaysia at the material time; or
  • the person affected by the offence is a Malaysian citizen.

This provision recognises the cross-border nature of cybercrime. However, while the Bill may establish Malaysia’s jurisdiction over an overseas cybercrime, practical enforcement may still depend on international cooperation and mutual legal assistance where the offender or relevant evidence is located outside Malaysia.

 

Does the Bill fill an existing gap in the law on intimate images?

Yes. Section 24 of the Bill introduces a specific offence for the dissemination of intimate images4 through a computer system. It covers a broad range of conduct, including transmitting, distributing, publishing, selling, offering for sale or otherwise making an intimate image available. This provision further distinguishes more serious conduct where the dissemination is carried out with the intention to cause humiliation or harm5, or to coerce or intimidate the person depicted. Further, it applies to intimate images of any person, including images that have been altered or manipulated.

Notably, this provision seeks to address limitations in existing laws, including Section 507E of the Penal Code and Section 8 of the Sexual Offences Against Children Act 2017, particularly where intimate images are disseminated through complex digital systems or across jurisdictions. It also extends protection beyond child victims to any person in general6.

 

What happens when a cybercrime affects critical infrastructure?

Section 25 of the Bill introduces an enhanced-penalty approach where specified cybercrime affects or involves a national critical information infrastructure (“NCII”) or NCII Entity. The penalties are structured according to the consequences of the offence, with substantially higher punishment where the conduct results in injury or loss of life. This creates a legal link between the regulatory framework for protecting NCII under the Cyber Security Act 2024 and the criminal consequences for certain cybercrime affecting NCII.

 

Conclusion

The Bill reflects a shift in the legal understanding of cybercrime, from conduct directed at computer systems to the wider misuse of technology as a tool for committing offences. The Bill also recognises the borderless nature of cybercrime through its extra-territorial application and its potential interaction with existing cybersecurity legislation. Businesses and organisations should review their cybersecurity governance, internal controls and incident-response arrangements to identify and mitigate potential legal and operational risks.

 


1. Section 3 of the Bill defines the term “computer system” as “any device or a group of interconnected or related devices, one or more of which, pursuant to a program, gathers, stores and performs automatic processing of computer data, including a computer”.
2. Section 3 of the Bill defines the term “computer data” as “any representation of facts, information or concepts in a form suitable for processing in a computer system which includes a program suitable to cause a computer system to perform a function, including content data, traffic data and subscriber information”.
3. Section 22(2) of the Bill defines the term “identity information” as “any information that identifies, or is capable of identifying or purports to identify, a person”.
4. Section 24(3) of the Bill defines the term “intimate image” as “a visual recording, including a photograph or video recording, made by any means, whether altered or otherwise, that is sexual in nature, in which the sexual parts of a person are exposed or a person is engaged in sexual activity”.
5. Section 24(3) of the Bill defines the term “harm” as “harm to a person’s body, mind, reputation or property, including psychological harm”.
6. https://hansard.parlimen.gov.my/hansard/dewan-rakyat/2026-07-01.

 

Written by:

Khairul Fazli Abdul Kadir (Partner) khairul.fazli@azmilaw.com

Khairunnisa Khairol Anwar (Senior Associate) khairunnisa@azmilaw.com

 

Corporate Communications, Azmi & Associates – 27 August 2026