Table of Contents Show
Malaysia recorded 66,204 cybercrime cases in 2025, up from 35,368 the year before. That is an 87 percent jump in a single year, and the losses tied to those cases climbed just as sharply, from RM1.57 billion in 2024 to RM2.97 billion in 2025. If your business has not looked closely at its cybersecurity exposure recently, these numbers are the reason to start now.
What makes this uncomfortable for business owners is that the growth is not slowing down. Parliament responded by passing the Cybercrimes Bill 2026, replacing legislation that dates back to 1997, precisely because the old framework could not keep pace with how these crimes have evolved. Here is what the data actually shows, and what it means for how you protect your business this year.

How Much Cyber Crime Actually Cost Malaysia Last Year
The RM2.97 billion in losses reported for 2025 covers a wide mix of financial scams, identity theft, data breaches, and online deception, and the trend has been building for a while. The Inspector-General of Police had already flagged losses exceeding RM1.22 billion for just the first ten months of 2024, a figure that made clear the problem was accelerating well before the full-year totals came in.
Cyber999, the national incident response centre, logged 2,020 incidents in the third quarter of 2025 alone, a jump of more than 20 percent from the same period the year before. Phishing and online fraud made up roughly 75 percent of those cases. That single number tells you where most businesses should be focusing their defences first.
Where Most of These Attacks Are Actually Coming From
Cyber attacks against Malaysian businesses cluster around a handful of methods that keep working because they exploit human behaviour, not just software flaws.
1. Phishing and Online Fraud
Phishing campaigns, fake e-commerce storefronts, and fraudulent payment links remain the most common way attackers get in, accounting for the bulk of Cyber999’s reported cases. These attacks do not need to break through a firewall. They only need one employee to click a convincing link or approve a fake invoice.
2. Ransomware
Ransomware attacks on Malaysian businesses rose 42 percent year on year in 2025, with a particularly sharp 78 percent surge recorded in the fourth quarter of 2024 alone. Typical ransom demands fall between RM500,000 and RM5 million, and the recovery costs, covering lost revenue, data restoration, and reputational damage, usually end up higher than the ransom itself.
3. QR Code and Payment Scams
Criminals have increasingly turned to QR codes and digital payment channels to intercept transactions, with scams spiking noticeably during festive periods when payment volumes surge. E-duit raya and similar seasonal payment habits have become a reliable hunting ground for this type of fraud.
Why Malaysian Businesses Sit in the Crosshairs
Malaysia ranked as the eighth most breached country globally in 2023, and the exposure has not eased since. A large part of the problem comes down to capability rather than intent. Research cited across the industry shows that 98 percent of Malaysian organisations have experienced breaches linked to talent shortages, meaning many businesses simply do not have enough trained people watching for threats before they turn into incidents.
That gap matters more for small and mid-sized businesses than it does for large corporations with dedicated security teams. A single successful ransomware attack, at the lower end of that RM500,000 to RM5 million demand range, can wipe out a year of profit for a smaller operation, before recovery costs are even factored in.
Businesses that handle high transaction volumes tend to feel this first. Retailers and e-commerce operators sit directly in the path of the phishing and payment fraud that make up most reported cases, while any company processing customer payment data becomes a more attractive target simply by virtue of what it holds. Size does not offer much protection either. Attackers increasingly favour smaller vendors precisely because they know larger clients further up the supply chain rarely check whether those vendors meet the same security standard they hold themselves to.
What the New Cybercrimes Bill 2026 Changes for Businesses
The Cybercrimes Bill 2026, passed by Parliament in July 2026, replaces the Computer Crimes Act 1997 and expands what counts as a prosecutable cyber offence. It now explicitly covers ransomware and malicious software attacks, AI-generated and digitally manipulated content such as deepfakes, identity theft, misuse of National Digital Identity credentials, and computer-related fraud.
For business owners, the practical effect is that your legal exposure now extends further than it used to. An incident involving deepfake content used to defraud a customer, or the misuse of digital identity credentials tied to your systems, falls under a framework built specifically to prosecute it. Security teams increasingly need to coordinate with legal, compliance, and communications functions rather than treating cyber risk as a purely technical problem.
Turning These Numbers Into a Cybersecurity Plan
The scale of these figures can feel paralysing, but the practical response is not complicated. Given that phishing and fraud account for three-quarters of reported cases, staff training on spotting fake invoices and suspicious links delivers more protection per ringgit spent than almost anything else. Keeping an eye on Bank Negara Malaysia’s financial fraud alerts is also a simple habit worth building, since it tracks the scam tactics currently circulating before they reach your staff or customers. Given that ransomware recovery costs routinely exceed the ransom demand, having tested backups and an incident response plan matters more than hoping an attack never lands.
The harder part for most businesses is knowing where their specific gaps are, especially with talent shortages making it difficult to build that expertise internally. This is where working with an established cybersecurity and data privacy advisory firm tends to close the gap faster than trying to hire and train a team from scratch, particularly for businesses that need a clear-eyed risk assessment before deciding where to invest.
A risk assessment done properly will tell you which of these numbers actually apply to your business, rather than leaving you to guess based on headlines. A logistics company with limited customer payment exposure faces a different risk profile from a fintech handling transactions every minute, and the controls that make sense for one will not necessarily make sense for the other.
The numbers for 2025 are already a warning. With cybercrime cases and losses both climbing sharply and a new legal framework raising the stakes further, treating cybersecurity as next year’s problem is no longer a safe bet for any business operating in Malaysia today.