What You Need To Know About The Cybercrime Bill 2026: Protecting The Innocent From Digital Sexual Abuse
Malaysia's current digital laws have fallen out of sync with 21st-century technological realities.
Follow us on Instagram, TikTok, and WhatsApp for the latest stories and breaking news.
Malaysia is poised to overhaul its digital security framework following the first reading of the Cybercrime Bill 2026 in the Dewan Rakyat
Tabled by Deputy Prime Minister Datuk Seri Dr Ahmad Zahid Hamidi, the proposed legislation aims to strengthen efforts to prevent and combat increasingly sophisticated digital threats nationwide, according to the New Straits Times.
Comprising eight parts and 61 clauses, the Bill is intended to equip law enforcement agencies with stronger powers to investigate and prosecute cybercrime.

The driving force behind this legislative shift is simple: Malaysia's current digital laws have fallen out of sync with 21st-century technological realities
The Cybercrime Bill 2026 will repeal the Computer Crimes Act 1997. While the older law was designed to address basic system intrusions and data theft, it does not account for modern threats such as ransomware, online fraud syndicates, and sophisticated identity theft networks.
The need for reform is underscored by rising financial losses from cybercrime, which increased by more than 86% to RM2.9 billion in 2025, as reported by The Edge.
The updated legal framework is intended to strengthen digital trust and support the growth of Malaysia's digital economy.
Among its key provisions, Clause 24 criminalises the non-consensual dissemination of intimate images
Anyone caught transmitting, distributing, or selling explicit sexual content through a computer system will face up to five years' imprisonment, a fine of up to RM300,000, or both. Harsher penalties apply if the material is shared with intent to cause humiliation, harm, or extortion.
The Bill also updates the definition of an 'intimate image' to include content created or altered using generative artificial intelligence and deepfake tools. This means that real, manipulated, or AI-generated sexual images that falsely depict an individual are treated equally under the law.

Image used for illustration purposes only.
Image via Sora Shimazaki/PexelsThe Bill extends into digital identity manipulation under Sections 22 and 23
Under Section 22, anyone who knowingly and without lawful authority uses a computer system to obtain, supply, use, or possess another person's personal identity data to commit or facilitate a crime faces up to seven years in prison, a fine of up to RM500,000, or both.
Section 23 addresses the creation of deceptively realistic synthetic or manipulated content. It criminalises the distribution of fake audio or visual media that closely resembles a real individual, place, object, or event and is presented as authentic to facilitate a crime.
Offenders face the same maximum penalty of seven years' imprisonment and a RM500,000 fine. This specific provision is intended to curb large-scale digital disinformation campaigns and highly realistic voice-cloning scams.
Beyond protecting domestic consumers, the Bill elevates Malaysia's baseline credibility on the international stage
The new legal parameters feature extra-territorial applications, meaning local authorities can comfortably pursue cybercriminals targeting Malaysians even if those operators are physically located outside national borders. This alignment ensures the country successfully satisfies its global obligations under both the Council of Europe Convention on Cybercrime, widely known as the Budapest Convention, and the United Nations Convention Against Cybercrime.
Structurally, the regulatory and law enforcement powers outlined in this Bill will be overseen by the National Cyber Security Agency (NACSA) under the National Security Council in the Prime Minister's Department. Following its successful first tabling, Zahid has confirmed that the Bill is scheduled for its second and third readings on 1 July 2026 for further debate.


Cover image via