Malaysia is moving to update its nearly 30-year-old cybercrime law with the Cybercrimes Bill 2026, which aims to equip authorities with tools to combat online fraud, digital impersonation, and AI-generated abuse. The bill, first tabled in parliament on June 22, received approval from the Dewan Rakyat, Malaysia’s lower house, on July 1, and was cleared by the Dewan Negara, the upper house, on Monday, pending royal assent and gazettement.
The Cybercrimes Bill 2026 will replace the Computer Crimes Act 1997, a framework established before the advent of smartphones, online banking, and platform scams. Deputy Prime Minister Ahmad Zahid Hamidi reported that there were 8,014 charges related to online fraud recorded from January to May this year, surpassing the 6,140 charges recorded throughout 2025.
Ahmad Zahid stated that these figures indicate a rise in both the frequency of online fraud and the financial losses incurred by victims. “Therefore, there is an urgent need to enact a comprehensive cybercrime law to deal with cybercrime more effectively, in line with the increasingly complex and sophisticated cybersecurity threat landscape,” he said.
As of May, 10,245 individuals had been arrested, with the majority of cases involving telecommunications, e-commerce, investment scams, and fraudulent loan offers. Cybersecurity experts noted that the bill could address significant legal gaps and enhance cooperation between enforcement agencies, giving Malaysian authorities broader jurisdiction over international cybercriminals.
However, experts cautioned that the bill’s success hinges on effective enforcement, forensic capabilities, and safeguards against the misuse of power. “It gives enforcement agencies more structured authority to act quickly when evidence may be altered or deleted, while officials have stressed that access is supposed to be limited to relevant data and subject to procedure,” said Mohamed Ridza Wahiddin, a cybersecurity expert at the International Islamic University Malaysia.
The legislation aims to expand the range of punishable cyber offenses and fill gaps in previous laws concerning scams, impersonation, and harmful online content dissemination. Mohamed Ridza emphasized that the bill is part of a broader national cybersecurity strategy, as modern cybercrime often intertwines fraud, identity abuse, and social engineering across various platforms and borders.
Ainuddin Wahid Abdul Wahab, a cybersecurity and digital forensics expert at Universiti Malaya, highlighted that the bill’s 61 clauses specify offenses not adequately addressed by the Computer Crimes Act 1997, such as online fraud, identity theft, unauthorized access to computer systems, AI-generated deepfakes, and the distribution of non-consensual intimate material.




