[codicts-css-switcher id=”346″]

Global Law Experts Logo
cybercrimes bill malaysia

Our Expert in Malaysia

Malaysia’s Cybercrimes Bill 2026, What Fintechs, Vasps and Payment Providers Need to Know

By Global Law Experts
– posted 2 hours ago

The cybercrimes bill malaysia has been discussing represents one of the most consequential regulatory shifts facing digital finance operators in the country, potentially redrawing the legal boundaries around unauthorised access, data interference and electronic evidence in ways that directly touch virtual asset service providers (VASPs), payment service providers (PSPs) and e-money issuers (EMIs). For compliance teams already juggling anti-money laundering (AML) obligations, licensing conditions and operational resilience expectations, proposed 2026 legislation of this kind would add a new layer of criminal-law exposure, incident-handling duties and evidentiary rules that must be operationalised rather than merely noted.

This article translates the anticipated architecture of such reform into practical steps for FinTech founders, general counsel, security officers and compliance leads, mapping offence definitions to real-world operational risks and setting out a prioritised roadmap for the next 180 days. Because cybercrime reform intersects with the supervisory reach of Bank Negara Malaysia (BNM), the Securities Commission Malaysia (SC), the Malaysian Communications and Multimedia Commission (MCMC) and CyberSecurity Malaysia, no single compliance function can address it in isolation. What follows is a practitioner-first playbook designed to be actionable, subject always to the final text of any Bill as published by the Attorney-General’s Chambers (AGC) and Parliament.

Readers should note that, as at the time of writing, the precise scope, drafting and commencement of any Cybercrimes Bill should be verified against the official AGC and Parliament sources, as the details below reflect the general direction of cybercrime law rather than a confirmed enacted statute.

Who this article is for: Founders, general counsel, compliance officers, security officers, and VASP/PSP technical leads operating in Malaysia.

What it delivers: A clear explanation of the kinds of provisions a Cybercrimes Bill would introduce that affect FinTech, concrete compliance actions, incident-handling considerations, the interaction with AML/CFT and licensing, plus a compliance checklist and template guidance.

Why a Cybercrimes Bill matters for FinTechs

The commercial premise of any FinTech, that value can move digitally, securely and at scale, is precisely what makes the sector a priority target for regulators addressing cybercrime. Reform of the cybercrimes framework in Malaysia would tighten the criminal rules around conduct that FinTechs experience daily: account takeovers, credential stuffing, malware injection into custodial systems and the interference with transaction data. The immediate significance is that these are no longer only operational security incidents; they may become events with defined offence categories, evidentiary consequences and, in the most serious cases, reporting duties. Malaysia already regulates much of this conduct through the Computer Crimes Act 1997, and reform would build on, rather than replace, that existing foundation.

For high-risk categories in particular, digital asset exchanges, custodial wallet providers and payment aggregators, three risks demand urgent attention:

  • New and expanded offences. Conduct such as unauthorised access, data interference and the misuse of devices may be defined with greater precision, creating clearer liability exposure for both individuals and corporate entities.
  • Incident-handling and evidentiary duties. Certain cyber incidents may trigger notification obligations, and modern reform typically strengthens rules on electronic evidence and its preservation, which changes how a FinTech must handle logs, forensic images and chain-of-custody documentation.
  • AML/CFT and licensing intersection. A cyber incident can simultaneously be an AML red flag and a potential breach of licence conditions, meaning a single event may require action across security, compliance and legal functions at once.

The practical takeaway is that cybersecurity is increasingly a cross-regulatory compliance obligation, not merely a technical concern. Firms that treat it purely as an IT matter will be exposed on the reporting, evidentiary and licensing fronts.

1. Key changes to watch (offences, evidentiary rules and new definitions)

The centre of gravity in cybercrime reform is its treatment of offences and evidence. FinTech compliance teams need to understand not only what is prohibited, but how conduct is defined, how it can be proven, and what corporate liability may attach. The precise drafting and pinpoint references should always be confirmed against the Computer Crimes Act 1997 and any Bill text published on the AGC and Parliament websites once finalised.

Offence categories affecting FinTech

The most operationally relevant offences for digital finance fall into several families, several of which are already addressed under the Computer Crimes Act 1997:

  • Unauthorised access. Gaining access to a computer system, account or data without authorisation. For a VASP, this maps directly to account takeover, unauthorised administrative access to hot wallets, and insider misuse of privileged credentials.
  • Data interference. The alteration, deletion or corruption of data. In a payments context, this covers tampering with transaction records, ledger manipulation and interference with settlement data.
  • Misuse of devices. The possession, distribution or use of tools designed to commit cyber offences, relevant where malware, phishing kits or credential-harvesting infrastructure target a FinTech’s customers or systems.

The importance of definitional precision cannot be overstated. Concepts such as “unauthorised access” and any requirement of intent determine whether an incident is criminal conduct, an internal control failure, or both. Where a customer’s credentials are stolen and used to drain a custodial account, the FinTech may simultaneously be a victim, a potential evidence custodian, and a reporting party, each role carrying distinct obligations.

Evidentiary and technical preservation rules

A defining feature of modern cybercrime legislation is the treatment of electronic evidence. In Malaysia, the admissibility of computer-generated evidence is already governed principally by the Evidence Act 1950. Reform may reinforce rules on how electronic evidence is defined, admitted and preserved, and may confirm investigatory powers to require production of, or to seize, devices and data. For FinTechs this has an immediate operational consequence: the logs, timestamps, transaction records and system snapshots generated during and after an incident may become evidence in a criminal matter.

The practical implications include:

  • Logging must be forensic-ready, accurate, tamper-evident and retained for sufficient periods to support later investigation.
  • Incident response must include an evidence-preservation step from the outset, rather than treating forensics as an afterthought once systems are restored.
  • Chain-of-custody discipline must extend to third-party providers, since much of a FinTech’s infrastructure sits with cloud and vendor partners.

Penalties, enforcement and corporate liability

Cybercrime frameworks of this kind typically combine criminal fines with custodial sentences for the most serious offences, and they increasingly attach liability to corporate entities and, in some cases, to directors and officers who fail to exercise adequate oversight. For a FinTech, corporate liability is the critical exposure: a firm that fails to maintain reasonable security controls, or that obstructs investigation by failing to preserve evidence, may face enforcement risk in addition to the reputational and financial harm of the incident itself. The exact penalty thresholds should be read directly from the applicable statute and any enacted reform, and firms should avoid assuming penalty levels until the legislation is finalised.

2. Who is in scope: VASPs, PSPs and EMIs

Cybercrime law applies broadly, but its practical bite for FinTechs is shaped by the overlay of financial-sector regulation. Understanding whether your business is treated as a VASP, PSP or EMI matters because that classification determines which supervisory authority expects what, and how a cyber incident cascades into licensing consequences.

Defining VASP and PSP under Malaysian regulators

In Malaysia, supervisory responsibility is divided principally between the Securities Commission Malaysia (SC) and Bank Negara Malaysia (BNM):

  • Digital asset businesses generally fall under the SC’s remit. The SC prescribes certain digital assets as securities under the Capital Markets and Services (Prescription of Securities) (Digital Currency and Digital Token) Order 2019, and regulates recognised market operators such as digital asset exchanges under its Guidelines on Digital Assets. It applies AML/CFT expectations consistent with international standards to such providers.
  • PSPs and e-money issuers generally fall under BNM’s remit, which regulates payment systems and payment instruments under the Financial Services Act 2013 (and, where relevant, the Islamic Financial Services Act 2013), including operational-risk resilience for payment service providers.

The classification is functional rather than nominal. A business that facilitates the exchange, transfer or custody of digital assets may fall within the SC’s framework regardless of how it markets itself, and a business that issues stored value or processes payments may fall within BNM’s payments framework. Firms should classify their activities against the relevant regulator’s definitions rather than relying on self-description. Note that Malaysia’s formal regime is currently framed around digital assets and capital-markets concepts rather than a standalone statutory “VASP” licence category, and the term “VASP” is used here in the broader international sense.

Overlap with regulated entities

Many FinTechs sit at the intersection of multiple regimes. A licensed bank offering digital wallet functionality, an e-money issuer that also facilitates crypto on-ramps, or a digital asset exchange that offers fiat payment rails may attract obligations from both the SC and BNM simultaneously. Under any cybercrime reform, all of these entities are potential targets of the same underlying offences, but their reporting and licensing consequences will differ according to which authority supervises them.

Examples and red flags

Certain business models require particularly careful classification:

  • Smart contract custodians that hold or control customer assets programmatically may still be treated as exercising custody for regulatory purposes.
  • Hybrid wallets combining self-custody and hosted elements can blur the line between an unregulated software provider and a regulated digital asset service provider.
  • Payment aggregators and gateways that touch settlement data sit squarely within both the payments framework and the data-interference offences.

Action: classify each product line against the SC and BNM tests, document the analysis, and identify which regulator you would notify in the event of a material cyber incident. This mapping is the foundation for the incident-reporting workflow described next.

3. Incident reporting obligations and timelines

Incident reporting is where cybercrime reform would converge most sharply with existing regulatory expectations. Reform may introduce reporting duties for certain categories of cyber incident, and any such duties would sit alongside, not replace, the sectoral reporting obligations that BNM, the SC and MCMC already administer. Note that Malaysia’s Cyber Security Act 2024 introduced obligations relating to national critical information infrastructure and incident notification for designated entities; whether a particular FinTech falls within that regime depends on designation. The exact thresholds and timelines must be confirmed from the applicable statutes and the relevant regulator circulars; the guidance below sets out how to build a workflow that adapts to whatever final parameters apply.

Building a reporting workflow

A robust incident-reporting workflow should proceed in defined stages:

  1. Detect and triage. Determine whether the event meets any reporting threshold, typically defined by severity, data affected, financial impact or the compromise of critical systems.
  2. Classify. Assess which regimes are engaged: any cybercrime reporting duty, obligations under the Cyber Security Act 2024 where applicable, BNM operational-risk notification, SC obligations for digital asset providers, MCMC communications-related duties, and AML suspicious-transaction reporting.
  3. Notify. Issue notifications to each relevant authority within the applicable deadline, using pre-approved templates.
  4. Preserve. Secure evidence in parallel with containment, maintaining chain of custody.
  5. Report and remediate. Provide follow-up reports as investigation progresses and document remediation.

Multi-regulator reporting coordination

The core practical challenge is that a single incident may need to be reported to several bodies, each with its own channel, format and timeframe. CyberSecurity Malaysia operates the national cyber emergency response team (MyCERT) and provides channels for incident notification and technical guidance. MCMC holds statutory powers over communications-related matters and may expect parallel reporting where communications infrastructure is implicated. BNM expects regulated payment providers to maintain cyber resilience and to notify it of material incidents in line with its risk-management guidance, while the SC applies analogous expectations to digital asset service providers. Law enforcement may also need to be engaged where a criminal offence has occurred.

Reporting trigger Likely recipient(s) Practical priority
Material compromise of customer funds or custodial assets Sector regulator (SC or BNM), law enforcement Immediate, highest severity
Unauthorised access constituting a criminal offence Law enforcement, sector regulator, CyberSecurity Malaysia (MyCERT) Urgent
Data breach affecting personal data Relevant data protection and sector authorities Urgent, per applicable notification window
Communications infrastructure compromise MCMC, CyberSecurity Malaysia (MyCERT) Prompt
Suspected money laundering linked to the incident AML reporting channel (STR to the Financial Intelligence and Enforcement Department, BNM) Per AML timelines

Note that Malaysia’s Personal Data Protection Act 2010 was amended in 2024 to introduce, among other things, data breach notification obligations to the Personal Data Protection Commissioner and affected data subjects; firms should confirm the applicable thresholds and timelines under the amended Act and its subsidiary guidance. Because different regimes may specify different windows, commonly ranging from immediate notification to fixed periods measured in hours or days for follow-up reporting, firms should adopt the shortest applicable deadline as the operational standard and confirm the precise figures against each regulator’s published guidance.

Template notice elements

Every regulator notification should be capable of stating, at minimum:

  • The nature and scope of the incident, including systems and data affected.
  • The time of detection and estimated time of occurrence.
  • The number of customers affected and any financial impact.
  • Containment and remediation steps taken and planned.
  • Evidence preserved and the preservation methodology.
  • Named contact points within the firm for follow-up.

4. AML/CFT and licensing impacts

The intersection of cybercrime and financial crime is where reform becomes most operationally demanding for digital asset providers and PSPs. A cyber incident is rarely just a security event; it frequently generates suspicious activity, and it can expose gaps in a firm’s AML/CFT programme or breach the conditions on which its licence was granted. In Malaysia, AML/CFT obligations arise principally under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA) and the sectoral guidelines issued by BNM and the SC.

How cyber offences map to AML red flags

Many cyber offences are also classic AML typologies:

  • Account takeovers frequently precede the laundering of stolen funds through a compromised account.
  • Credential stuffing at scale can indicate an organised effort to open or hijack accounts for illicit fund movement.
  • Data interference with transaction records may be used to obscure the source or destination of funds.

Where a cyber incident produces indicators of money laundering, the firm’s AML obligations to file suspicious transaction reports under the AMLA are engaged in parallel with any cyber incident-reporting duties. The Financial Action Task Force (FATF) framework treats VASPs as obliged entities within AML/CFT regimes and expects cooperation with law enforcement, reinforcing that a cyber-driven AML event cannot be handled solely by the security team.

Licensing triggers for digital asset providers and PSPs

A material cyber incident can act as a trigger for regulatory re-assessment. Where an incident reveals that a licensee or registered operator failed to maintain the customer due diligence, transaction monitoring or operational-resilience standards required, the regulator may treat the event as evidence of non-compliance. Consequences can range from enhanced supervision and remediation directions through to conditions on, or in the most serious cases revocation or withdrawal of, an authorisation. For digital asset providers supervised by the SC and payment providers supervised by BNM, the message is consistent: cyber resilience is a regulatory obligation, not an optional extra.

Practical steps for compliance teams

  • Update AML policies so that defined cyber incidents automatically trigger a suspicious-transaction assessment.
  • Integrate the incident-response and AML workflows so that a single event cannot fall between the two functions.
  • Apply enhanced due diligence to accounts implicated in a cyber incident before restoring full functionality.
  • Document the linkage between cyber and AML decisions to demonstrate a joined-up compliance posture to regulators.

5. Operational compliance: governance, incident response and evidence preservation

Translating cybercrime reform into day-to-day practice requires changes across governance, incident response and evidence handling. This is the section that converts legal analysis into an operating model.

Governance and board oversight

Cyber and financial-crime resilience is a board-level responsibility. Firms should:

  • Assign clear ownership, typically a named incident-response (IR) lead supported by defined roles across security, legal, compliance and communications.
  • Establish reporting lines that ensure material incidents reach senior management and the board without delay.
  • Review and update information-security, incident-response, evidence-preservation and AML policies to reflect current obligations.
  • Ensure the board receives regular reporting on cyber risk, near-misses and the outcome of testing exercises.

Incident response playbook essentials

An effective playbook covers the full lifecycle of an incident and should include, at minimum:

  • Detection and triage criteria that map directly to reporting thresholds.
  • Containment steps that stop harm without destroying evidence.
  • Forensics conducted by, or under the supervision of, qualified specialists.
  • Regulator and law-enforcement notification using pre-approved templates and decision trees.
  • Customer and market communication that is accurate and consistent with regulatory expectations.
  • Post-incident review feeding lessons back into controls and policies.

Evidence preservation and chain of custody

Given the evidentiary rules governing electronic evidence, evidence preservation deserves particular attention. CyberSecurity Malaysia publishes guidance relevant to incident handling and preservation, and firms should align their practices accordingly. Core requirements include:

  • Preserving technical logs, timestamps and system state before remediation overwrites them.
  • Creating forensic images of affected systems where feasible.
  • Documenting who accessed evidence, when, and for what purpose, maintaining an unbroken chain of custody.
  • Handling potentially privileged material carefully, consistent with professional-conduct considerations around evidence and lawyer-client privilege.

Vendor and cloud-provider obligations

Most FinTechs depend on third-party infrastructure, so compliance cannot stop at the firm’s own perimeter. Contracts and service-level agreements with cloud and vendor partners should:

  • Require prompt incident notification to the FinTech within a defined window.
  • Commit the provider to preserve logs and support evidence collection.
  • Grant audit and information rights sufficient to satisfy regulator inquiries.
  • Allocate responsibilities clearly so that no reporting or preservation step is left unassigned.
Responsibility Primary owner Supporting function
Incident detection and triage Security / IR lead IT operations
Regulator notification Compliance / Legal IR lead
Evidence preservation Forensics / IR lead Vendor / cloud provider
AML assessment (STR) AML / Compliance Security
Customer communication Communications Legal
Board reporting General counsel / CISO Compliance

6. Practical compliance checklist and immediate steps

The following prioritised roadmap helps FinTech compliance teams prepare for cybercrime reform over the next 90 to 180 days. Assign an owner and a deadline to each item.

  1. Appoint an incident-response lead with authority across security, legal and compliance. (Owner: CEO/GC, 30 days)
  2. Classify each product line against SC and BNM definitions to confirm digital asset / PSP / EMI status. (Owner: Legal, 30 days)
  3. Map reporting obligations across cybercrime and cyber security law, BNM, SC, MCMC, CyberSecurity Malaysia, data protection and AML channels. (Owner: Compliance, 45 days)
  4. Update information-security and incident-response policies to reflect current offences and duties. (Owner: CISO/Compliance, 60 days)
  5. Build regulator notification templates covering the required notice elements. (Owner: Legal, 60 days)
  6. Implement forensic-ready logging with appropriate retention and tamper-evidence. (Owner: IT/Security, 90 days)
  7. Adopt an evidence-preservation and chain-of-custody procedure. (Owner: Security/Legal, 90 days)
  8. Integrate cyber and AML workflows so incidents trigger suspicious-transaction assessment. (Owner: AML/Compliance, 90 days)
  9. Review vendor and cloud contracts for notification, preservation and audit clauses. (Owner: Legal/Procurement, 120 days)
  10. Run a tabletop exercise simulating a custodial-asset compromise and multi-regulator reporting. (Owner: IR lead, 120 days)
  11. Brief the board on cyber exposure, licensing risk and remediation status. (Owner: GC/CISO, 150 days)
  12. Establish an ongoing review cadence to update the programme as legislation and regulator guidance evolve. (Owner: Compliance, 180 days)

Supporting internal documents to develop include an incident report template, an evidence-preservation checklist, and a regulator-notification template. For a deeper operational treatment, consider developing a Cyber Incident Response Checklist tailored to VASPs and PSPs in Malaysia, and a digital asset licensing reference aligned to the SC’s Guidelines on Digital Assets.

7. Comparison: proposed cybercrime reform vs the current regime vs AML obligations

The table below summarises how anticipated reform, the existing position and AML/CFT obligations interact. It is indicative and should be read alongside the applicable statutes (including the Computer Crimes Act 1997, the Cyber Security Act 2024 and the Evidence Act 1950), any final Bill text and current regulator guidance.

Topic Anticipated cybercrime reform Current regime AML/CFT impact
Offence definitions Potentially expanded and clarified offences (unauthorised access, data interference, misuse of devices) Established framework under the Computer Crimes Act 1997 Many cyber offences overlap with AML typologies
Corporate liability Potentially strengthened exposure for entities and, possibly, officers More limited corporate exposure under existing law Failures may indicate weak AML controls
Reporting obligations Possible additional incident-reporting duties for defined incidents Sector-specific duties plus Cyber Security Act 2024 for designated entities Parallel STR filing where laundering suspected
Evidentiary powers Potentially reinforced rules on electronic evidence and preservation Evidence Act 1950 and general investigatory powers Preserved evidence supports AML investigations
Penalties Fines and custodial sentences for serious offences (to be confirmed from final text) Existing penalty structure Enforcement can compound AML sanctions
Regulator coordination Cross-regulator engagement (BNM, SC, MCMC, CyberSecurity Malaysia) Largely sector-by-sector AML authority engaged alongside cyber regulators
Cross-border evidence Framework relevant to preserving and sharing electronic evidence Reliance on existing mutual assistance mechanisms Supports international AML cooperation (FATF standards)

Conclusion

Cybercrime reform is not a peripheral compliance matter for digital finance, it reshapes the criminal, evidentiary and reporting landscape in which every VASP, PSP and EMI operates. The firms that fare best will treat cybersecurity, AML/CFT and licensing as a single, integrated obligation, supported by clear governance, forensic-ready operations and multi-regulator reporting workflows. Because cybercrime law intersects with the supervisory expectations of BNM, the SC, MCMC and CyberSecurity Malaysia, with the Cyber Security Act 2024 and data protection obligations, and with international AML/CFT standards, the compliance response must be cross-functional and led from the top.

Begin with the prioritised roadmap in Section 6, verify every specific obligation against the applicable statutes and any final text published by the AGC and Parliament, and revisit your programme as regulator guidance develops. Acting now, before the first serious incident tests your controls, is the most reliable way to convert evolving cybercrime requirements into a durable competitive and compliance advantage.

This article is provided for general information only and does not constitute legal advice. The status, scope and content of any Cybercrimes Bill referenced should be independently verified, as it may not have been enacted. FinTechs should obtain advice from Malaysia-qualified counsel on the application of current and proposed cybercrime, cyber security, data protection and financial-services law to their specific circumstances, and should confirm all statutory references and reporting timelines against the final enacted text and current regulator guidance.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Sabir Alijev at LegalBison, a member of the Global Law Experts network.

Sources

  1. Attorney-General’s Chambers of Malaysia (AGC)
  2. Parliament of Malaysia (Parlimen), Bills & Acts
  3. Malaysian Communications and Multimedia Commission (MCMC)
  4. CyberSecurity Malaysia
  5. Bank Negara Malaysia (BNM)
  6. Securities Commission Malaysia (SC)
  7. The Malaysian Bar (Bar Council)
  8. Financial Action Task Force (FATF)

FAQs

What cyber security and offence provisions could affect FinTechs and crypto exchanges?
The main offences relevant to FinTechs are unauthorised access, data interference and the misuse of devices, much of which is already addressed under the Computer Crimes Act 1997. For custodial services and exchanges, these translate directly into criminal-law exposure for account takeovers, ledger tampering and malware-driven attacks. See Section 1 and confirm the pinpoint references against the applicable statutes and any Bill text on the AGC and Parliament sites.
Reform may introduce reporting duties for defined cyber incidents, which would sit alongside existing BNM, SC and MCMC expectations, the Cyber Security Act 2024 (for designated entities) and data breach notification under the amended Personal Data Protection Act 2010. Timelines vary by regime and severity, so firms should adopt the shortest applicable deadline as their operating standard. Confirm exact thresholds from the enacted text and regulator guidance, and see Section 3.
Where a cyber incident produces indicators of money laundering, AML reporting duties under the AMLA are triggered in parallel with any cyber incident-reporting duties. VASPs are treated as obliged entities under AML/CFT frameworks consistent with FATF standards, so cyber and AML workflows must be integrated. See Section 4.
Appoint an incident-response lead, update security and AML policies, implement forensic-ready logging, and secure vendor commitments on notification and preservation. Chain-of-custody discipline is essential given the rules on electronic evidence. See Section 5 for the operating model.
Yes. Where an incident exposes material non-compliance with regulatory conditions, such as inadequate transaction monitoring or operational resilience, the SC or BNM may treat it as grounds for supervisory action, up to and including conditions on, or in serious cases withdrawal of, an authorisation. See Section 4.
It depends on the incident and the applicable thresholds. Where a criminal offence has occurred and material harm is involved, both may need to be engaged, often on parallel timelines. Build a decision tree into your incident-response playbook so notifications are not delayed by uncertainty. See Section 3.
Section 6 sets out the supporting documents every FinTech should develop, including an incident report template, an evidence-preservation checklist and a regulator-notification template. Bespoke templates should be adapted to your specific authorisation category and regulator relationships.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Malaysia’s Cybercrimes Bill 2026, What Fintechs, Vasps and Payment Providers Need to Know

Send welcome message

Custom Message