Senator Dr Lingeshwaran R. Arunasalam added that protecting Malaysia’s digital ecosystem should not stop at defending against external cyberattacks but must also address vulnerabilities arising from within public institutions
PETALING JAYA: While the Cyber Crimes Bill targets cyber offences such as hacking and digitally manipulated content including deepfakes, Senator Dr Lingeshwaran R. Arunasalam has proposed expanding the law to address insider negligence, suppression, concealment and manipulation of government digital records.
He said cases such as former fugitive Tamim Dahri and the long-running Indira Gandhi custody dispute highlight the need to examine whether insider negligence, suppression, concealment or manipulation of government digital records could undermine law enforcement and the administration of justice.
“If public officials misuse their privileged access to deny citizens information they are lawfully entitled to, or to obstruct justice, that too undermines the integrity of our critical digital infrastructure,” he told theSun, adding that both cases point to gaps within government digital systems.
On Indira Gandhi’s case, he questioned why Muhammad Riduan Abdullah and the couple’s kidnapped daughter remained untraceable, and why the National Registration Department had refused to release the daughter’s records to Indira, a citizen with a legitimate legal claim to them.
“Is there any reason why Indira’s former husband and her kidnapped daughter still cannot be traced in this highly sophisticated digital era?” he asked, while pointing out that the more recent case of Tamim similarly exposed such gaps.
He raised the Tamim case during the Cyber Crimes Bill 2026 debate in the Dewan Negara on Monday, saying Home Minister Saifuddin Nasution had stated in a written parliamentary reply on July 14 that police applied for an Interpol Red Notice against Tamim on June 8, and that Immigration Department checks indicated he was still overseas.
“Yet allegations have since emerged that he was able to leave and re-enter the country.”
Lingeshwaran questioned whether the incident was the result of simple human error or whether it exposed deeper cybersecurity failures at the country’s border entry points.
He also asked whether the Immigration Department’s databases, blacklist alert systems and biometric screening had been compromised, tampered with internally or disrupted by server communication breakdowns.
“If someone already on the authorities’ radar could enter the country this easily, what then of individuals with intent to commit violence or threaten national security?”
Likening cybercrime to an aggressive cancer spreading through society, he said the Computer Crimes Act 1997 was an “expired medicine” that could no longer combat evolving digital threats.
He said the new law would become “a tiger without teeth” if enforcement agencies such as the police, National Cyber Security Agency and the Malaysian Communications and Multimedia Commission were not equipped with adequate funding, digital forensic capabilities and operational resources.
He added that protecting Malaysia’s digital ecosystem should not stop at defending against external cyberattacks but must also address vulnerabilities arising from within public institutions, especially when privileged access to government digital systems could be abused or negligence could compromise justice.
Lingeshwaran also proposed mandatory migration from outdated SMS one-time passwords to stronger cryptographic or biometric authentication methods, saying preventing cybercrime was as important as punishing offenders.
He also called for mandatory independent cybersecurity audits for organisations managing critical national data, wider adoption of zero-trust security architecture and baseline encryption standards to ensure that even if government systems were breached, stolen data would remain unreadable and unusable to cybercriminals.
“The Cyber Crimes Bill 2026 is not merely a tool for compliance with international conventions, it is an instrument of national security.”









