Malaysia cracks down on cybercrime with new rules for digital space: ‘necessary reset’

Malaysia is close to overhauling its nearly 30-year-old cybercrime law and giving authorities long-sought tools to pursue online fraud, digital impersonation and AI-generated abuse, but…

Malaysia is close to overhauling its nearly 30-year-old cybercrime law and giving authorities long-sought tools to pursue online fraud, digital impersonation and AI-generated abuse, but experts say the bill’s impact will depend on whether investigators can enforce it effectively and prevent misuse of its powers.

The Cybercrimes Bill 2026 was first tabled in parliament on June 22 and passed by the Dewan Rakyat, Malaysia’s lower house, on July 1. The Dewan Negara, the upper house, approved it on Monday, moving it a step closer to becoming law, pending royal assent and gazettement.

The bill would replace the Computer Crimes Act 1997, a nearly three-decade-old framework enacted long before smartphones, online banking, platform scams and generative artificial intelligence became part of everyday life.

Deputy Prime Minister Ahmad Zahid Hamidi told parliament during the second reading on Monday that 8,014 charges related to online fraud were recorded between January and May this year, surpassing the 6,140 recorded throughout 2025.

Ahmad Zahid said the figures showed that online fraud was increasing in both frequency and the financial losses inflicted on victims.

“Therefore, there is an urgent need to enact a comprehensive cybercrime law to deal with cybercrime more effectively, in line with the increasingly complex and sophisticated cybersecurity threat landscape,” he said.