Malaysia’s Dewan Negara passes the Cyber Security Bill 2026 to strengthen laws against complex cyber threats, with extraditable offences.
KUALA LUMPUR: The Dewan Negara today passed the Cyber Security Bill 2026 to bolster the country’s legal framework in addressing increasingly complex cyber threats.
The Bill, comprising eight parts and 61 clauses, which was drafted to repeal the Computer Crimes Act 1997, was passed by a majority vote after being debated by 21 senators. It was unanimously approved without amendments at the committee stage.
During the winding-up debate, Deputy Minister of Rural and Regional Development Datuk Rubiah Wang said all offences under the Cyber Security Bill 2026 are extraditable, as the Bill provides for a minimum jail sentence of three years.
She said under the Extradition Act 1992, any offence punishable with imprisonment of at least one year is classified as an extraditable offence.
“Since the minimum jail sentence provided under the Cyber Security Bill 2026 is three years, all offences under this Bill are automatically classified as extraditable,” she said.
Rubiah said the government will continue to enhance international cooperation through mechanisms such as Mutual Legal Assistance, INTERPOL, ASEANAPOL, and police-to-police collaboration, as well as through its adherence to the Budapest Convention and the United Nations Convention against Cybercrime.
She added that to obtain digital evidence and testimonies, including conducting searches and seizures abroad and tracking perpetrators, the government will rely on provisions under the Mutual Assistance in Criminal Matters Act 2002.
She clarified that the Cyber Security Bill 2026 does not seek to regulate technologies like AI per se. Instead, it is designed to take legal action against the abuse of such technologies for criminal activities, including fraud, election interference and sexual exploitation.
The government further stressed that the Bill is not aimed at curbing freedom of speech, academic inquiry, or journalism conducted within the bounds of the law.
“Any action can only be taken when all elements of the offence, as provided under the Bill, are successfully proven through investigation and court proceedings,” Rubiah said.
During the debate, Senator Datuk Salehuddin Saidin urged the government to review the Bill to ensure heavier penalties are imposed on large-scale online fraud syndicates. He also called for the inclusion of a mechanism for direct compensation to victims.
Senator Dr Wan Martina Wan Yusoff suggested that the Bill should include a specific section on victims’ rights, covering the right to apply for court orders to remove content, seek compensation and restore digital identity.
Meanwhile, Senator Dr A. Lingeshwaran called on financial service providers and telecommunications companies to move beyond SMS OTP towards more secure biometric or cryptographic authentication systems, and to implement regular, independent cybersecurity audits.
The Bill was presented for its second reading in the Dewan Negara today by Deputy Prime Minister Datuk Seri Dr Ahmad Zahid Hamidi.
The Dewan Negara sitting resumes tomorrow.









