
As a department that specialises in technology related matters, we have certainly dealt with a fair number of cyber incidents. Not all of these cyber incidents however involved hacked servers, computer viruses or fending off ferocious attacks from threat actors. There are more companies that have lost their money to social engineering attacks than one would have thought – making payment to a supplier’s invoice with an apparently changed bank account, or an approval that came from what seemed to be the managing director for a payment request that seemed to be legit. In these situations, nobody broke into the systems or servers of the companies, but yet money was taken out of the companies.
The narrative above somewhat describes the gap that the Computer Crimes Act 1997 (“CCA”) faced. In the CCA, almost every offence deals with someone getting into a computer system without authorisation, which was fair given the nature of computer crime back in 1997. In today’s age however, with the advent of artificial intelligence, proliferation of social engineering schemes and identity theft, the CCA is no longer an adequate tool. The CCA contains no fraud offence, no forgery offence and no identity theft offence. When dealing with a case involving any one of these elements, the prosecutors will have to rely on the Penal Code to pin down the perpetrators, with no specific law enacted for the purpose.
The Cybercrimes Bill 2026 that was passed in Malaysia a couple of months ago is the instrument tasked to address the gap faced by the CCA. We have addressed in one of our earlier articles the top 7 key takeaways concerning the Cybercrimes Bill 2026, so now in this article, we will be doing a deeper dive into the inner workings of this piece of legislation, and how it may apply to organisations. We will be focussing on the conducts and activities that are now additionally being criminalised under the Cybercrimes Bill 2026 that were not previously tackled by the CCA.
1. Activities Being Outlawed
- i) Computer-Related Forgery and Fraud
Among the examples given at the beginning of this article, we mentioned the use of a falsified invoice and a forged director’s approval to trick employees into making unauthorised payments. These conducts are now captured under Section 16 of the Cybercrimes Bill 2026. The section expressly criminalises any input, alteration, deletion or suppression of computer data, resulting in inauthentic computer data with the intention that such computer data be considered or acted upon as if the computer data were authentic.
Even impersonation, in some ways, is caught by the Cybercrimes Bill 2026 too. In the case where someone deliberately creates an email account that looks deceptively like the email account of the managing partner of a law firm and instructs the release of certain stakeholder sum to a third-party bank account, the conduct would be caught under Section 17 of the Bill as a computer-related fraud. A catch in this regard however, is that there must be loss of property to another person before Section 17 is actionable.
Interestingly, the Bill defines “property” widely, referring to asset of every kind, even intangible property such as virtual asset and digital currency. This is certainly good news for companies that are operating in the digital space, such as the likes of the digital asset exchanges and digital asset custodians in Malaysia, who would be holding on to large amounts of digital assets. From this, we can see that the Bill is attempting to ensure that the net cast to catch the cybercriminals is as wide as possible.
- ii) Phishing
Phishing is certainly something that many have experienced, through the occasional emails informing the winning of jackpots, or Microsoft seemingly requesting a reset of passwords. Phishing is being criminalised under the Bill through several provisions.
Sections 15 and 20 of the Bill are where phishing is being dealt with. If a person intentionally and without authority or lawful purpose, obtains a password, access credentials, electronic signature or similar computer data, with the intention of gaining access to a device or computer data for the committing of an offence under the Bill, he can be found liable.
- iii) Manipulation of Records
Cybersecurity incidents do not usually stop at gaining access to the targeted systems. What is fearful about cybersecurity incidents is oftentimes what comes after the access – deployment of ransomware, denial of access by the system owners, and even deletion or modification of data. These conducts are now being criminalised under the Bill, in particular pursuant to Section 13. Any person who intentionally and without authority or lawful purpose, damages, deletes or alters computer data; or obstructs, interrupts or interferes with the lawful use of computer data; or denies access to computer data to any person entitled to it, would be committing an offence under the Bill.
- iv) Insider Misuse of Credentials
There is this Chinese saying that you can protect against many things, but the hardest thing to guard against is a thief in your own home. This very aptly describes the fact that some of the most successful cybersecurity incidents ever reported rely on an inside mole. An employee stealing or facilitating a heist from the company he is working for can be charged under the Penal Code, and possibly also liable for breach of employment terms and/or fiduciary duty. With the passing of the Bill, the same employee can also be charged pursuant to Section 21 of the Bill for wrongfully communicating a credential to access the company’s computer system to someone who is not authorised to have access. What is extremely useful to note here is that an employee can be held liable under Section 21 even without an intention to cause harm to the company or an intention for the credential disclosed to be used to commit further offence. The fact that there was an unauthorised disclosure of credential itself is enough to trigger the section.
2. Obligations of Service Providers
It is unsurprising that many would think the Cybercrimes Bill 2026 only concerns the criminalisation of cybercrimes. This is however only partially true – the Bill also imposes certain obligations on a specific category of service providers.
The group of service providers that are subject to additional obligations under the Bill are those that:
- a) Provide services to their users which entail the ability to communicate through a computer system;
- b) Process or store computer data relating to communications service; or
- c) Provide information and communication service, including telecommunications.
On a plain reading, it would seem like the category of service providers the Bill is trying to reach is the telecommunication service providers. But upon a more careful read, it would appear that e-commerce marketplace operators, ride-hailing platform operators, gaming platform operators, and any other applications or platforms with messaging features may potentially also be caught, due to the potentially wide construct of the definition of “service provider” under the Bill. In addition, the hosting service providers and any third-party processors engaged by these platform operators would seemingly also be captured under the definition of “service provider”. While the exact scope of the “service provider” is yet to be tested under the Malaysian legal framework, companies who are potentially caught under the definition should at least be mindful of the obligations imposed by the Bill.
Presently, the Bill imposes a duty on the defined service providers to take necessary measures to prevent any services provided by them from being used to commit cybercrimes. Officers who are authorised under the Bill may issue written notice to these service providers requiring them to take specific measures to prevent the commission or attempted commission of any cybercrime, or to assist the enforcement in relation to any cybercrime. Additionally, the Bill also empowers the Public Prosecutor to require the service providers to collect or record traffic data and content data of its services or platforms in real time, and/or to intercept a specified communication, and to furnish such data to the officers authorised under the Bill. Failure on the part of the service providers to cooperate and to comply with the directions given to them constitutes offences under the Bill.
So, if you think that the Cybercrimes Bill 2026 only concerns actual cybercriminals and has nothing to do with companies running legitimate businesses, think again.
Looking at the Cybercrimes Bill 2026 as a whole, it is certainly a much-welcomed addition to the legal arsenals of the government in combating cybercrimes. It addresses some of the gaps and pain points faced by the CCA as illustrated above. After all, as technology evolves, more and more cyber risks that we have never faced before will surface, and our legislation will have to evolve accordingly to keep pace with the current cybersecurity landscape.
While the Cybercrimes Bill 2026 sought to criminalise conducts that have been rather elusive under the currently in force CCA, it also seeks to create certain obligations on the part of a selected category of service providers who may just be the best placed to further insulate the public from cybercrimes. Essentially, the Bill is not only looking at punishing and deterring cybercrimes but also creating avenues to enhance the overall cyber-resilience of the nation.
That said, a well-drafted statute is only one half of the equation. The hard truth about cybercrime is that most perpetrators operate from behind rented infrastructure, borrowed identities and foreign borders, and they rarely announce themselves. Identifying who actually sat at the keyboard remains the single greatest obstacle to enforcement, and no amount of drafting can solve it on its own. The Cybercrimes Bill 2026 does provide the tools that matter most in this regard, namely the powers to preserve, compel and intercept data held by service providers, but those tools reach only as far as the parties within Malaysia’s jurisdictional grasp. The real measure of this legislation, then, will not be found in the elegance of its offences, but in how effectively our enforcement agencies use these new powers, how quickly organisations respond when an incident occurs, and how far international cooperation can be made to work in practice.
If you have any questions on the Cybercrimes Bill 2026, cybersecurity regulation, cyber incident response, data breaches, AI-related risks, technology compliance or the broader technology regulatory framework in Malaysia, please feel free to reach out to the partners in our Technology Practice Group, Lo Khai Yi and Ong Johnson, for a consultation. We have extensive experience advising on technology law, cybersecurity, data protection, AI, digital platforms, and regulatory compliance matters in Malaysia, and would be pleased to assist businesses, boards and in-house teams in understanding the implications of the evolving cybercrime framework and preparing for the legal, regulatory and operational requirements ahead.
The Technology Practice Group of Halim Hong & Quek continues to be recognised by leading legal directories and industry benchmarks. Recent accolades include FinTech Law Firm of the Year at the ALB Malaysia Law Awards (2024, 2025 and 2026), Law Firm of the Year for Technology, Media and Telecommunications by the In-House Community, FinTech Law Firm of the Year by the Asia Business Law Journal, a Band 2 ranking for FinTech by Chambers and Partners, and a Tier 3 ranking by Legal 500. The strength of the practice is further reflected in the individual recognition of its partners, including a Band 1 ranking for FinTech by Chambers and Partners within the Technology Practice Group.
About the authors
Lo Khai Yi
Partner
Co-Head of Technology Practice Group
Technology, Media & Telecommunications (“TMT”), Technology
Acquisition and Outsourcing, Telecommunication Licensing and
Acquisition, Cybersecurity
ky.lo@hhq.com.my.
◦
Ong Johnson
Partner
Head of Technology Practice Group
Fintech, Data Protection,
Technology, Media & Telecommunications (“TMT”),
IP and Competition Law
johnson.ong@hhq.com.my
More of our Tech articles that you should read:
- • Consumer Credit Act 2025: 10 Key Takeaways on Malaysia’s New Authorisation Regime
- • Exit and Step-In Rights in Artificial Intelligence-as-a-Service
- •Telecommunication Towers M&A: Unpacking the Transaction