˂  Back

Cybercrimes Bill 2026: Top 7 Key Takeaways on AI Deepfakes, Identity Theft, Cyberattacks and Corporate Liability

On the technology law front, with the rise of AI, and especially agentic AI, there is no doubt that technology has brought tremendous gains in productivity, efficiency and effectiveness across society, workplaces, corporations and businesses. But there is always another side of the same coin.

 

As technology continues to advance, particularly with AI, cybercrime is also evolving just as quickly. Within the past 18 months alone, we have seen the complexity and sophistication of cybercrime evolve significantly, from ransomware and online fraud to identity theft, AI-enabled impersonation, deepfakes and manipulated intimate images that are deeply disturbing, and even national crisis-level cyberattacks capable of disrupting essential national services. As the saying goes, the law will eventually catch up with technological evolution. It is therefore unsurprising that many technology lawyers are now paying close attention to the latest development of the Cybercrimes Bill 2026, which is designed specifically to address many of these emerging concerns.

 

As previously discussed, Malaysia’s technology legal framework is still actively expanding. We have seen the introduction of the Cyber Security Act 2024, followed by the amendments to the Personal Data Protection Act 2010 and the passing of the Online Safety Act 2025, and now all eyes are on the Cybercrimes Bill 2026 as the next important piece in further strengthening Malaysia’s broader technology law framework. The Cybercrimes Bill 2026 is an especially interesting read for legal practitioners specialising in technology law, particularly those actively dealing with data breaches, cybersecurity incidents and cyberattacks, as it is more than simply a technical update to an ageing statute, but it introduces a new and substantially broader architecture covering a wider and more comprehensive range of modern cyber offences.

 

With that, in this article, we aim to set out the top 7 key takeaways from the Cybercrimes Bill 2026 that companies, boards, senior management, in-house counsel, compliance teams, technology providers and cybersecurity professionals should pay close attention to. Like it or not, whether at a personal or professional level, cybercrime is never too far away from us, as the current technology landscape increasingly demonstrates. We trust that this article will be particularly helpful in providing a practical understanding of what is coming, what organisations should be paying attention to, and how they can begin preparing for this new and important chapter of cybercrime regulation in Malaysia.

 

Key Takeaway 1: The Current Legislative Status of the Cybercrimes Bill 2026

 

Of course, the starting point for every piece of draft legislation is to understand precisely where it currently stands.

 

The Cybercrimes Bill 2026 was successfully passed by the Dewan Rakyat on 1 July 2026, following its first reading on 22 June 2026, and was subsequently passed by the Dewan Negara on 20 July 2026.

 

Following its passage by both Houses of Parliament, what we are now waiting for is the completion of the remaining legislative steps and the commencement of the resulting Act. Once enacted, the legislation will be cited as the Cybercrimes Act 2026, while clause 1(2) of the Cybercrimes Bill 2026 provides that the resulting Act will come into operation on a date to be appointed by the Minister by notification in the Gazette.

 

Reading the current movement and momentum in this area, there should be little doubt that the actual commencement date may not be too far away, particularly given the importance of this piece of legislation in addressing the rising tide and increasing sophistication of cybercrime. Hence, while the law has yet to come into force, it would be wise for all in-house legal, compliance and technology teams to at least familiarise themselves with the new framework and begin preparing where necessary.

 

 

Key Takeaway 2: What Is the Key Purpose of the Cybercrimes Bill 2026?

 

The second key takeaway is to understand the fundamental intention behind the Cybercrimes Bill 2026.

 

At its core, the intention of the Cybercrimes Bill 2026 is to repeal the increasingly archaic Computer Crimes Act 1997 and establish a new and more comprehensive legal framework to prevent and combat modern forms of cybercrime that have emerged alongside the rapid development of technology.

 

In fact, the Explanatory Statement within the Cybercrimes Bill 2026 makes this particularly clear that this proposed new law is necessitated by the rapid advancement of digital technology, the borderless nature of cyberspace and the increasingly sophisticated nature of cybercrime activities, which are capable of threatening national security, the economy, public order and personal safety. In other words, the law is being modernised because the nature, scale and consequences of cybercrime have themselves fundamentally changed.

 

This is also precisely why the Cybercrimes Bill 2026 is both so timely and so crucial, as over the past 18 months alone, the data and incidents we have seen point clearly towards a continuing rise in all forms of data breaches, cyber incidents, cyberattacks and related cybercrimes. Against this backdrop, a more modern and comprehensive cybercrime framework is exactly what Malaysia needs to better respond to the increasingly complex risks accompanying technological advancement, and the Cybercrimes Bill 2026 is intended to do exactly that.

 

 

Key Takeaway 3: What Are Some of the Core Cybercrimes Under the Cybercrimes Bill 2026?

 

The Cybercrimes Bill 2026 in fact covers a wide range of different cybercrimes and, without listing everything, some of the key core cybercrimes are as follows:

 

  • • Unauthorised access to a computer system – punishable by a fine of up to RM100,000, imprisonment for up to three years, or both.
  • • Unauthorised access to a computer system with the intention of committing or facilitating a further offence involving fraud or dishonesty, or which causes injury as defined in the Penal Code – punishable by a fine of up to RM500,000, imprisonment for up to seven years, or both.
  • • Unauthorised interception by technical means of non-public computer-data transmissions – punishable by a fine of up to RM500,000, imprisonment for up to seven years, or both.
  • • Interference with computer data, including damaging, deleting, altering, suppressing or rendering data meaningless or inaccessible – punishable by a fine of up to RM100,000, imprisonment for up to three years, or both.
  • • Interference with the functioning or lawful operation of computer systems, where the conduct seriously hinders the functioning or lawful use of a computer system – punishable by a fine of up to RM500,000, imprisonment for up to seven years, or both.
  • • Computer-related forgery, involving the input, alteration, deletion or suppression of computer data resulting in inauthentic data intended to be considered or acted upon for a legal purpose as though it were authentic. Where valuable security is involved, the penalty is fine up to RM500,000, imprisonment for up to seven years, or both. In other cases, the maximum penalty is a fine of RM300,000, imprisonment for up to five years, or both.
  • • Computer-related fraud, involving the manipulation of computer data or systems, or deception through a computer system, resulting in loss of property to another person with a fraudulent or dishonest intention to obtain an economic benefit – punishable by a fine of up to RM1,000,000, imprisonment for up to 10 years, or both.

 

From the above, it is clear that many of the core cybercrimes under the Cybercrimes Bill 2026 are drafted broadly enough to address a wide range of digital criminal conduct that we have increasingly seen in practice, ranging from more conventional forms of hacking and ransomware to newer and increasingly sophisticated conduct such as phishing, fraudulent payment instructions, manipulation of electronic records, digital-asset fraud and abuse of access credentials.

 

For the longest time, one of the recurring frustrations surrounding cybercrime has been the perception that there is often limited recourse against threat actors or offenders. Therefore, the offences proposed within the Cybercrimes Bill 2026 seek to address some of the most crucial aspects of modern cybercrime and are deliberately wide enough to capture different forms of unauthorised access, interference, manipulation, deception and fraud involving computer systems and data. This is definitely a crucial development because the law is no longer looking only at the traditional concept of “hacking”, but at the much broader range of conduct through which technology can now be misused to cause financial, operational and personal harm.

 

Key Takeaway 4: Identity Theft Is Expressly Addressed as an Offence Under the Cybercrimes Bill 2026

 

One particularly interesting takeaway from the Cybercrimes Bill 2026 is that it introduces identity theft as a specific offence.

 

The Cybercrimes Bill 2026 makes it clear that where a person intentionally and without authority or lawful purpose, through a computer system, obtains, supplies, uses, possesses or controls another person’s identity information with the intention of committing or facilitating any offence under any written law, that person shall, upon conviction, be liable to a fine of up to RM500,000, imprisonment for up to seven years, or both. In the above context, “identity information” is widely defined to include any information that identifies, is capable of identifying or purports to identify a person.

 

This is particularly significant in today’s data-breach landscape, where a cyberattack rarely ends with ransomware or the mere exfiltration of data. More often than not, once information has been compromised, threat actors go on to misuse the identity information to carry out further offences. Indeed, one only needs to follow the news to see that one of the most serious second-order consequences of a data breach is the subsequent misuse of stolen identity information, which can then lead to even greater harm, including impersonation, account takeover, fraudulent onboarding and social-engineering attacks. Technology professionals would therefore appreciate that the damage from a cyberattack does not necessarily end when the data leaves the system, and in many cases, that is actually only where the next stage of the harm begins.

 

Therefore, this is without doubt a positive and important development because, as mentioned in Key Takeaway 3, unauthorised access to a computer system is already an offence under the Cybercrimes Bill 2026, but it also goes one step further by addressing one of the most common second-order consequences of such cyber incidents, which is identity theft itself. This certainly makes the new framework even more comprehensive and better aligned with the realities of how modern cybercrime actually unfolds.

 

Key Takeaway 5: The Criminal Misuse of AI Deepfakes Is Addressed by the Cybercrimes Bill 2026

 

Besides the introduction of identity theft, another development that is particularly worth taking note of is closely related to the rise of AI deepfakes, where the Cybercrimes Bill 2026 also addresses generated or manipulated visual and audio content. The Cybercrimes Bill 2026 makes it clear that any person who transmits, distributes, publishes, sells or otherwise makes available any visual or audio content generated or manipulated through a computer system that resembles an existing person, object, place, entity or event, falsely appears to be authentic or truthful, and is used with the intention of committing or facilitating another offence under any written law, commits an offence and shall, upon conviction, be liable to a fine of up to RM500,000, imprisonment for up to seven years, or both.

 

In recent months, we have increasingly been reading news of people falling victim to scams involving AI deepfakes. For example, a threat actor may use AI-generated video or audio to impersonate a senior executive directing an urgent payment, before pressuring an employee to immediately make the transfer. Equally concerning, a threat actor may impersonate a family member through an AI-generated voice or video and deceive an elderly family member into urgently transferring money.

 

Therefore, with the rise of AI deepfakes, the Cybercrimes Bill 2026 specifically seeks to address this concern. However, what is particularly sensible about the approach is that it does not outright ban all AI deepfakes, or every AI-generated image, video or audio recording, because there are, after all, always two sides to the same coin. AI-generated content can be entirely legitimate and beneficial when used in advertising, entertainment, education, product development and many other contexts with proper authorisation and disclosure. The criminal concern arises when deepfake or AI-generated content is deliberately deployed as an instrument to commit or facilitate fraud, extortion or another offence involving impersonation or deception.

 

This is, without doubt, another strong illustration of how the Cybercrimes Bill 2026 is designed around the realities of the latest technology and cyber-threat landscape, as rather than focusing only on conventional forms of cybercrime like hacking, the Cybercrimes Bill 2026 recognises that the methods used by threat actors are rapidly evolving alongside AI and other emerging technologies, and seeks to ensure that the legal framework is sufficiently broad and forward-looking to address these newer forms of digital misconduct.

 

Key Takeaway 6: Where the Cybercrimes Bill 2026 Meets the Cyber Security Act 2024

 

Another particularly crucial aspect is where the Cybercrimes Bill 2026 also meets the Cyber Security Act 2024, which we have discussed at length in many of our previous articles.

 

The Cybercrimes Bill 2026 makes it clear that where some of the cybercrimes such that concern the unauthorized access, hacking, data interception, and data or system interference, or computer-related forgery or fraud, which affect or involve a national critical information infrastructure (“NCII“) entity or NCII, the punishment is substantially enhanced, with the penalties escalating depending on the severity of the harm caused:

 

  • Where the relevant offence involves loss of life, it is punishable with imprisonment for a term of between 30 and 40 years, a fine of up to RM2 million, or both.
  • Where the offence involves injury to any person, it is punishable with imprisonment for up to 15 years, a fine of up to RM1.5 million, or both.
  • •  In other qualifying cases, it is punishable with imprisonment for up to 10 years, a fine of up to RM1 million, or both.

 

One thing that immediately stands out to everyone is just how serious and severe these penalties are, but that is neither incidental nor difficult to understand, because these provisions are not concerned merely with attacks on ordinary IT systems or a company’s internal computer systems, but with attacks involving NCII.

 

Under the Cyber Security Act 2024, NCII refers to a computer or computer system whose disruption or destruction would have a detrimental impact on the delivery of services essential to Malaysia’s security, defence, foreign relations, economy, public health, public safety or public order, or on the ability of the Federal or State Governments to carry out their functions effectively. In that sense, NCII can be understood as forming part of the backbone of our national security, economy, social stability and business continuity. Therefore, any attack against an NCII entity or NCII can carry consequences far more serious than a random attack on an ordinary IT or computer system.

 

For instance, imagine a cyberattack against NCII within the nationwide healthcare and hospital sector that results in the widespread collapse or serious disruption of essential healthcare services. The consequences could be unimaginable, with potentially irreversible damage extending well beyond the affected organisation and into society and the nation as a whole.

 

It is therefore encouraging to see that the Cybercrimes Bill 2026 has not been drafted in isolation, but instead actively supplements other technology-related frameworks such as the Cyber Security Act 2024, much in the same way that the provisions on identity theft complement the legal framework under the Personal Data Protection Act 2010. Rather than competing with or creating contradictions between different pieces of legislation, the Cybercrimes Bill 2026 increasingly appear to supplement one another and, taken together, further complete Malaysia’s broader technology legal framework as a whole.

 

Key Takeaway 7: Who Will Then Be Responsible If the Company Commits an Offence?

 

Pretty much across all compliance training concerning technology law, one of the most practical and frequently raised questions is this: if an offence is actually committed by the company, then who exactly will be held liable and responsible?

 

The Cybercrimes Bill 2026 addresses exactly this point, where it makes it clear that where an offence is committed by a company, limited liability partnership, firm, society or other body of persons, any person who, at the time of the commission of the offence, was a director, compliance officer, partner, manager, secretary or similar person responsible for or assisting in the management of the organisation may be charged together with the organisation. More crucially, and very similarly to how the provisions of the Personal Data Protection Act 2010 are drafted, if the organisation is found guilty, those individuals may also be deemed guilty unless they can establish either that the offence was committed without their knowledge, or that it was committed without their consent or connivance and that they had taken all reasonable precautions and exercised due diligence to prevent the commission of the offence.

 

Given that there is such a deeming provision under the Cybercrimes Bill 2026, where a company commits an offence, key stakeholders including directors, compliance officers and managers may therefore be charged and potentially deemed guilty if the company itself is found guilty. It is therefore extremely crucial for companies and their senior management to ensure that they are able to establish a proper defence by demonstrating either that the offence was committed without their knowledge, or that it was committed without their consent or connivance and that all reasonable precautions had been taken and due diligence exercised to prevent the commission of such an offence.

 

From a practical compliance perspective, this means companies should take concrete preventative steps, including providing regular compliance training to employees, putting in place proper employee handbooks, policies and manuals setting out the relevant dos and don’ts, establishing clear guardrails on the boundaries that must not be crossed, and making sure employees are properly educated and trained on both the consequences of non-compliance and the steps required to prevent such offences.

 

There is no doubt that a deeming provision of this nature may understandably appear daunting to directors and senior management, however, it is ultimately preventive in nature and its broader effect can still be positive, as it places responsibility not only on the individual who directly commits the wrongdoing, but also encourages organisations collectively to raise the baseline of governance, compliance awareness and cyber responsibility across the organisation. Eventually, the stronger the internal controls, training and compliance culture, the stronger the technology environment becomes as a whole for the country.

 

Closing Thoughts

 

Malaysia’s technology law landscape is clearly entering a new phase. What we are seeing is no longer a collection of isolated laws, but an increasingly connected legal architecture, with the Personal Data Protection Act 2010, Cyber Security Act 2024, Online Safety Act 2025 and now the Cybercrimes Bill 2026 gradually filling the gaps between data, systems, platforms, cyber threats and emerging technologies. The direction is absolutely clear that as technology advances, the law is steadily catching up, and each new piece of legislation is beginning to complete another part of the wider regulatory picture.

 

Therefore, while technology law may still be relatively young in Malaysia, it should already be at the forefront of every in-house legal and compliance agenda. Technology is no longer merely a function of the business, but increasingly, technology is the business, from AI and data to cybersecurity, payments, communications and digital infrastructure, almost every organisation will inevitably be touched by these developments. Hence, legal in-house teams that pay attention early, understand what is coming and build the right internal capability now will be far better placed to guide their organisations confidently through the next chapter of Malaysia’s technology regulatory evolution.

 

If you have any questions on the Cybercrimes Bill 2026, cybersecurity regulation, cyber incident response, data breaches, AI-related risks, technology compliance or the broader technology regulatory framework in Malaysia, please feel free to reach out to the partners in our Technology Practice Group, Ong Johnson and Lo Khai Yi, for a consultation. We have extensive experience advising on technology law, cybersecurity, data protection, AI, digital platforms, and regulatory compliance matters in Malaysia, and would be pleased to assist businesses, boards and in-house teams in understanding the implications of the evolving cybercrime framework and preparing for the legal, regulatory and operational requirements ahead.

 

The Technology Practice Group of Halim Hong & Quek continues to be recognised by leading legal directories and industry benchmarks. Recent accolades include FinTech Law Firm of the Year at the ALB Malaysia Law Awards (2024, 2025 and 2026), Law Firm of the Year for Technology, Media and Telecommunications by the In-House Community, FinTech Law Firm of the Year by the Asia Business Law Journal, a Band 2 ranking for FinTech by Chambers and Partners, and a Tier 3 ranking by Legal 500. The strength of the practice is further reflected in the individual recognition of its partners, including a Band 1 ranking for FinTech by Chambers and Partners within the Technology Practice Group.


About the authors

Ong Johnson
Partner
Head of Technology Practice Group

Fintech, Data Protection,
Technology, Media & Telecommunications (“TMT”),
IP and Competition Law
johnson.ong@hhq.com.my

Lo Khai Yi
Partner
Co-Head of Technology Practice Group
Technology, Media & Telecommunications (“TMT”), Technology
Acquisition and Outsourcing, Telecommunication Licensing and
Acquisition, Cybersecurity
ky.lo@hhq.com.my.


More of our Tech articles that you should read:

Our Services

© 2026 Halim Hong & Quek