KINIGUIDE | The government has tabled the Cybercrimes Bill, a major legislative overhaul intended to replace the nearly 30-year-old Computer Crimes Act legislated in 1997.

The bill seeks to offer more robust law enforcement against ever-evolving cyber threats, but critics are concerned about extensive overreach and government spying.

This Kiniguide explores what is in the bill and why some are calling for it to face deeper parliamentary scrutiny.

What’s this bill about?

The bill creates a comprehensive legal framework to prevent and combat cybercrimes, ranging from hacking and data interference to modern threats like deepfakes.

It establishes a centralised Committee on Combating Cybercrimes, chaired by the chief secretary to the government, to coordinate national strategies across various enforcement agencies.

Notably, the law has extra-territorial application, meaning it applies to anyone, regardless of nationality, if the target is a Malaysian or if any devices, systems, or data are in or passed through Malaysia.

The government argues that the rapid advancement of digital technology and the increasingly sophisticated, borderless nature of cybercrime have made the 1997 law obsolete.

How does the law define computer systems?

Computer systems, as defined by the law, would also cover smartphones, tablets and any other device that “gathers, stores and performs automatic processing of computer data” - leaving the definition of computer systems very wide.

How does this law keep me safe?

The bill introduces specific protections against modern digital harms:

Deepfakes and AI deception: Clause 23 specifically targets the distribution of visual or audio content generated or manipulated by a computer system that falsely appears to be authentic, and covers offences under any law.

For sharing such content with the intention to commit or facilitate a crime, offenders face a fine of up to RM500,000, imprisonment for up to seven years, or both.

Revenge porn: Clause 24 criminalises the dissemination of intimate images, including those that are altered or entirely generated by AI such as "deepfake porn".

Simply transmitting or distributing such images carries a penalty of up to five years in prison, a fine of up to RM300,000, or both.

If the images are shared with the specific intent to humiliate, harm, coerce, or intimidate the victim, the penalty increases to up to seven years in prison, a fine of up to RM500,000, or both.

Scams: Under Clause 17, using a computer to cause a loss of property with the dishonest intention to gain an economic benefit is punishable by a fine of up to RM1 million, imprisonment for up to 10 years, or both.

Meanwhile, using a computer system to obtain or use another person's identity information to commit a crime is punishable by up to seven years in prison, a fine of up to RM500,000, or both.

Critical infrastructure: Clause 25 introduces massive penalties for cybercrimes affecting national critical information infrastructure (NCII).

These generally refer to computer systems or networks that are essential to national security, the economy, public health, or safety, such as power grids, water systems, and emergency services.

If a cyber offence involving NCII results in a loss of life, the perpetrator faces a minimum of 30 years to a maximum of 40 years in prison, a fine of up to RM2 million, or both.

If the attack causes injury to any person, the penalty is up to 15 years in prison, a fine of up to RM1.5 million, or both.

Any other NCII-related offence carries a fine of up to RM1 million, imprisonment for up to 10 years, or both.

Fraud and hacking: The bill updates penalties for traditional computer crimes to deal with modern scale.

Basic unauthorised access to a computer system (Clause 10) carries a fine of up to RM100,000, up to three years' jail, or both.

If the hacking is done with the intent to commit fraud or cause injury (Clause 11), the penalty jumps to a fine of up to RM500,000, up to seven years' jail, or both.

Possession of hacking tools is also a punishable offence.

Does this affect my online presence?

There are new statutory presumptions regarding your MyDigital ID.

Under Clause 19, if a user shares their national digital ID credentials for any gain and those credentials are used to commit a crime, the law rebuttably presumes the user knew the credentials would be used for an illegal purpose.

Obtaining and retaining those credentials for criminal purposes is also an offence.

Additionally, service providers - which can include social media apps - are mandated to take "necessary measures" to prevent their platforms from being used for cybercrimes.

Will this affect VPN users?

The extra-territorial clause in the bill covers offences if the computer system, programme, or data was in Malaysia or connected to a system, programme or data in the country.

This will likely mean that using a Malaysian VPN server or accessing data stored locally will fall under the ambit of the law.

Can the government use this to spy on me?

The bill grants broad surveillance powers to prosecutors and authorised officers.

Among others, authorities can require service providers to collect and record your traffic data - who you talk to, when, and for how long - in real-time.

Authorities can also intercept and record the actual contents of your communications, such as messages, voice recordings, and videos.

Prosecutors can even authorise the installation of interception devices in any premises, including your home, without a warrant.

This surveillance is not restricted to cybercrimes and can be used to investigate any offence under any other written law if it was committed using a computer.

Potentially this means that those investigated for sedition, criminal defamation, and other political offences could be subject to this extensive surveillance.

Service providers are legally prohibited from disclosing that your data is being monitored or intercepted.

Authorised officers with the rank of inspector and above can perform warrantless searches and seizures of devices if they believe a delay would result in evidence being tampered with or destroyed.

Can this be used against government critics?

The Malaysian Media Council (MMC) has warned that the bill is "overreaching" and lacks sufficient safeguards to protect constitutional liberties.

Because prosecutors can authorise data collection and interception without prior judicial approval, there are concerns that the law could be used to identify confidential journalistic sources or whistleblowers.

The MMC fears these powers may create a "chilling effect" on investigative journalism and the ability of citizens to seek confidential legal advice. The National Union of Journalists have expressed similar concerns.

Meanwhile, there are also concerns about the wording of Clause 23.

While it appears primarily aimed at deepfakes, the fact that it covers offences under any law and has vague enough wording raises concerns that it could be used against AI-generated or AI-assisted content which the government disagrees with.

This could impact the ability to use AI to produce parodies, satire, or criticise the government.

What other concerns are there?

Critics, including the MMC, have pointed out several missing "robust safeguards".

This includes a lack of judicial oversight, as many intrusive measures require only the prosecutor’s authorisation rather than a court order.

Further, there is no explicit protection in the bill for privileged communications between lawyers and clients.

Meanwhile, under Clause 36, anyone must provide their passwords and decryption codes to officers during a search.

Individuals served with notices to preserve or disclose data are barred from telling anyone about the notice, with unauthorised disclosure itself being a crime.

The MMC has formally proposed that the bill be referred to a parliamentary special select committee for more public deliberation and expert input before it is passed.