Our Expert in Malaysia
No results available
The cybercrimes bill malaysia has been discussing represents one of the most consequential regulatory shifts facing digital finance operators in the country, potentially redrawing the legal boundaries around unauthorised access, data interference and electronic evidence in ways that directly touch virtual asset service providers (VASPs), payment service providers (PSPs) and e-money issuers (EMIs). For compliance teams already juggling anti-money laundering (AML) obligations, licensing conditions and operational resilience expectations, proposed 2026 legislation of this kind would add a new layer of criminal-law exposure, incident-handling duties and evidentiary rules that must be operationalised rather than merely noted.
This article translates the anticipated architecture of such reform into practical steps for FinTech founders, general counsel, security officers and compliance leads, mapping offence definitions to real-world operational risks and setting out a prioritised roadmap for the next 180 days. Because cybercrime reform intersects with the supervisory reach of Bank Negara Malaysia (BNM), the Securities Commission Malaysia (SC), the Malaysian Communications and Multimedia Commission (MCMC) and CyberSecurity Malaysia, no single compliance function can address it in isolation. What follows is a practitioner-first playbook designed to be actionable, subject always to the final text of any Bill as published by the Attorney-General’s Chambers (AGC) and Parliament.
Readers should note that, as at the time of writing, the precise scope, drafting and commencement of any Cybercrimes Bill should be verified against the official AGC and Parliament sources, as the details below reflect the general direction of cybercrime law rather than a confirmed enacted statute.
Who this article is for: Founders, general counsel, compliance officers, security officers, and VASP/PSP technical leads operating in Malaysia.
What it delivers: A clear explanation of the kinds of provisions a Cybercrimes Bill would introduce that affect FinTech, concrete compliance actions, incident-handling considerations, the interaction with AML/CFT and licensing, plus a compliance checklist and template guidance.
The commercial premise of any FinTech, that value can move digitally, securely and at scale, is precisely what makes the sector a priority target for regulators addressing cybercrime. Reform of the cybercrimes framework in Malaysia would tighten the criminal rules around conduct that FinTechs experience daily: account takeovers, credential stuffing, malware injection into custodial systems and the interference with transaction data. The immediate significance is that these are no longer only operational security incidents; they may become events with defined offence categories, evidentiary consequences and, in the most serious cases, reporting duties. Malaysia already regulates much of this conduct through the Computer Crimes Act 1997, and reform would build on, rather than replace, that existing foundation.
For high-risk categories in particular, digital asset exchanges, custodial wallet providers and payment aggregators, three risks demand urgent attention:
The practical takeaway is that cybersecurity is increasingly a cross-regulatory compliance obligation, not merely a technical concern. Firms that treat it purely as an IT matter will be exposed on the reporting, evidentiary and licensing fronts.
The centre of gravity in cybercrime reform is its treatment of offences and evidence. FinTech compliance teams need to understand not only what is prohibited, but how conduct is defined, how it can be proven, and what corporate liability may attach. The precise drafting and pinpoint references should always be confirmed against the Computer Crimes Act 1997 and any Bill text published on the AGC and Parliament websites once finalised.
The most operationally relevant offences for digital finance fall into several families, several of which are already addressed under the Computer Crimes Act 1997:
The importance of definitional precision cannot be overstated. Concepts such as “unauthorised access” and any requirement of intent determine whether an incident is criminal conduct, an internal control failure, or both. Where a customer’s credentials are stolen and used to drain a custodial account, the FinTech may simultaneously be a victim, a potential evidence custodian, and a reporting party, each role carrying distinct obligations.
A defining feature of modern cybercrime legislation is the treatment of electronic evidence. In Malaysia, the admissibility of computer-generated evidence is already governed principally by the Evidence Act 1950. Reform may reinforce rules on how electronic evidence is defined, admitted and preserved, and may confirm investigatory powers to require production of, or to seize, devices and data. For FinTechs this has an immediate operational consequence: the logs, timestamps, transaction records and system snapshots generated during and after an incident may become evidence in a criminal matter.
The practical implications include:
Cybercrime frameworks of this kind typically combine criminal fines with custodial sentences for the most serious offences, and they increasingly attach liability to corporate entities and, in some cases, to directors and officers who fail to exercise adequate oversight. For a FinTech, corporate liability is the critical exposure: a firm that fails to maintain reasonable security controls, or that obstructs investigation by failing to preserve evidence, may face enforcement risk in addition to the reputational and financial harm of the incident itself. The exact penalty thresholds should be read directly from the applicable statute and any enacted reform, and firms should avoid assuming penalty levels until the legislation is finalised.
Cybercrime law applies broadly, but its practical bite for FinTechs is shaped by the overlay of financial-sector regulation. Understanding whether your business is treated as a VASP, PSP or EMI matters because that classification determines which supervisory authority expects what, and how a cyber incident cascades into licensing consequences.
In Malaysia, supervisory responsibility is divided principally between the Securities Commission Malaysia (SC) and Bank Negara Malaysia (BNM):
The classification is functional rather than nominal. A business that facilitates the exchange, transfer or custody of digital assets may fall within the SC’s framework regardless of how it markets itself, and a business that issues stored value or processes payments may fall within BNM’s payments framework. Firms should classify their activities against the relevant regulator’s definitions rather than relying on self-description. Note that Malaysia’s formal regime is currently framed around digital assets and capital-markets concepts rather than a standalone statutory “VASP” licence category, and the term “VASP” is used here in the broader international sense.
Many FinTechs sit at the intersection of multiple regimes. A licensed bank offering digital wallet functionality, an e-money issuer that also facilitates crypto on-ramps, or a digital asset exchange that offers fiat payment rails may attract obligations from both the SC and BNM simultaneously. Under any cybercrime reform, all of these entities are potential targets of the same underlying offences, but their reporting and licensing consequences will differ according to which authority supervises them.
Certain business models require particularly careful classification:
Action: classify each product line against the SC and BNM tests, document the analysis, and identify which regulator you would notify in the event of a material cyber incident. This mapping is the foundation for the incident-reporting workflow described next.
Incident reporting is where cybercrime reform would converge most sharply with existing regulatory expectations. Reform may introduce reporting duties for certain categories of cyber incident, and any such duties would sit alongside, not replace, the sectoral reporting obligations that BNM, the SC and MCMC already administer. Note that Malaysia’s Cyber Security Act 2024 introduced obligations relating to national critical information infrastructure and incident notification for designated entities; whether a particular FinTech falls within that regime depends on designation. The exact thresholds and timelines must be confirmed from the applicable statutes and the relevant regulator circulars; the guidance below sets out how to build a workflow that adapts to whatever final parameters apply.
A robust incident-reporting workflow should proceed in defined stages:
The core practical challenge is that a single incident may need to be reported to several bodies, each with its own channel, format and timeframe. CyberSecurity Malaysia operates the national cyber emergency response team (MyCERT) and provides channels for incident notification and technical guidance. MCMC holds statutory powers over communications-related matters and may expect parallel reporting where communications infrastructure is implicated. BNM expects regulated payment providers to maintain cyber resilience and to notify it of material incidents in line with its risk-management guidance, while the SC applies analogous expectations to digital asset service providers. Law enforcement may also need to be engaged where a criminal offence has occurred.
| Reporting trigger | Likely recipient(s) | Practical priority |
|---|---|---|
| Material compromise of customer funds or custodial assets | Sector regulator (SC or BNM), law enforcement | Immediate, highest severity |
| Unauthorised access constituting a criminal offence | Law enforcement, sector regulator, CyberSecurity Malaysia (MyCERT) | Urgent |
| Data breach affecting personal data | Relevant data protection and sector authorities | Urgent, per applicable notification window |
| Communications infrastructure compromise | MCMC, CyberSecurity Malaysia (MyCERT) | Prompt |
| Suspected money laundering linked to the incident | AML reporting channel (STR to the Financial Intelligence and Enforcement Department, BNM) | Per AML timelines |
Note that Malaysia’s Personal Data Protection Act 2010 was amended in 2024 to introduce, among other things, data breach notification obligations to the Personal Data Protection Commissioner and affected data subjects; firms should confirm the applicable thresholds and timelines under the amended Act and its subsidiary guidance. Because different regimes may specify different windows, commonly ranging from immediate notification to fixed periods measured in hours or days for follow-up reporting, firms should adopt the shortest applicable deadline as the operational standard and confirm the precise figures against each regulator’s published guidance.
Every regulator notification should be capable of stating, at minimum:
The intersection of cybercrime and financial crime is where reform becomes most operationally demanding for digital asset providers and PSPs. A cyber incident is rarely just a security event; it frequently generates suspicious activity, and it can expose gaps in a firm’s AML/CFT programme or breach the conditions on which its licence was granted. In Malaysia, AML/CFT obligations arise principally under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA) and the sectoral guidelines issued by BNM and the SC.
Many cyber offences are also classic AML typologies:
Where a cyber incident produces indicators of money laundering, the firm’s AML obligations to file suspicious transaction reports under the AMLA are engaged in parallel with any cyber incident-reporting duties. The Financial Action Task Force (FATF) framework treats VASPs as obliged entities within AML/CFT regimes and expects cooperation with law enforcement, reinforcing that a cyber-driven AML event cannot be handled solely by the security team.
A material cyber incident can act as a trigger for regulatory re-assessment. Where an incident reveals that a licensee or registered operator failed to maintain the customer due diligence, transaction monitoring or operational-resilience standards required, the regulator may treat the event as evidence of non-compliance. Consequences can range from enhanced supervision and remediation directions through to conditions on, or in the most serious cases revocation or withdrawal of, an authorisation. For digital asset providers supervised by the SC and payment providers supervised by BNM, the message is consistent: cyber resilience is a regulatory obligation, not an optional extra.
Translating cybercrime reform into day-to-day practice requires changes across governance, incident response and evidence handling. This is the section that converts legal analysis into an operating model.
Cyber and financial-crime resilience is a board-level responsibility. Firms should:
An effective playbook covers the full lifecycle of an incident and should include, at minimum:
Given the evidentiary rules governing electronic evidence, evidence preservation deserves particular attention. CyberSecurity Malaysia publishes guidance relevant to incident handling and preservation, and firms should align their practices accordingly. Core requirements include:
Most FinTechs depend on third-party infrastructure, so compliance cannot stop at the firm’s own perimeter. Contracts and service-level agreements with cloud and vendor partners should:
| Responsibility | Primary owner | Supporting function |
|---|---|---|
| Incident detection and triage | Security / IR lead | IT operations |
| Regulator notification | Compliance / Legal | IR lead |
| Evidence preservation | Forensics / IR lead | Vendor / cloud provider |
| AML assessment (STR) | AML / Compliance | Security |
| Customer communication | Communications | Legal |
| Board reporting | General counsel / CISO | Compliance |
The following prioritised roadmap helps FinTech compliance teams prepare for cybercrime reform over the next 90 to 180 days. Assign an owner and a deadline to each item.
Supporting internal documents to develop include an incident report template, an evidence-preservation checklist, and a regulator-notification template. For a deeper operational treatment, consider developing a Cyber Incident Response Checklist tailored to VASPs and PSPs in Malaysia, and a digital asset licensing reference aligned to the SC’s Guidelines on Digital Assets.
The table below summarises how anticipated reform, the existing position and AML/CFT obligations interact. It is indicative and should be read alongside the applicable statutes (including the Computer Crimes Act 1997, the Cyber Security Act 2024 and the Evidence Act 1950), any final Bill text and current regulator guidance.
| Topic | Anticipated cybercrime reform | Current regime | AML/CFT impact |
|---|---|---|---|
| Offence definitions | Potentially expanded and clarified offences (unauthorised access, data interference, misuse of devices) | Established framework under the Computer Crimes Act 1997 | Many cyber offences overlap with AML typologies |
| Corporate liability | Potentially strengthened exposure for entities and, possibly, officers | More limited corporate exposure under existing law | Failures may indicate weak AML controls |
| Reporting obligations | Possible additional incident-reporting duties for defined incidents | Sector-specific duties plus Cyber Security Act 2024 for designated entities | Parallel STR filing where laundering suspected |
| Evidentiary powers | Potentially reinforced rules on electronic evidence and preservation | Evidence Act 1950 and general investigatory powers | Preserved evidence supports AML investigations |
| Penalties | Fines and custodial sentences for serious offences (to be confirmed from final text) | Existing penalty structure | Enforcement can compound AML sanctions |
| Regulator coordination | Cross-regulator engagement (BNM, SC, MCMC, CyberSecurity Malaysia) | Largely sector-by-sector | AML authority engaged alongside cyber regulators |
| Cross-border evidence | Framework relevant to preserving and sharing electronic evidence | Reliance on existing mutual assistance mechanisms | Supports international AML cooperation (FATF standards) |
Cybercrime reform is not a peripheral compliance matter for digital finance, it reshapes the criminal, evidentiary and reporting landscape in which every VASP, PSP and EMI operates. The firms that fare best will treat cybersecurity, AML/CFT and licensing as a single, integrated obligation, supported by clear governance, forensic-ready operations and multi-regulator reporting workflows. Because cybercrime law intersects with the supervisory expectations of BNM, the SC, MCMC and CyberSecurity Malaysia, with the Cyber Security Act 2024 and data protection obligations, and with international AML/CFT standards, the compliance response must be cross-functional and led from the top.
Begin with the prioritised roadmap in Section 6, verify every specific obligation against the applicable statutes and any final text published by the AGC and Parliament, and revisit your programme as regulator guidance develops. Acting now, before the first serious incident tests your controls, is the most reliable way to convert evolving cybercrime requirements into a durable competitive and compliance advantage.
This article is provided for general information only and does not constitute legal advice. The status, scope and content of any Cybercrimes Bill referenced should be independently verified, as it may not have been enacted. FinTechs should obtain advice from Malaysia-qualified counsel on the application of current and proposed cybercrime, cyber security, data protection and financial-services law to their specific circumstances, and should confirm all statutory references and reporting timelines against the final enacted text and current regulator guidance.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Sabir Alijev at LegalBison, a member of the Global Law Experts network.
posted 12 minutes ago
posted 33 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message