Security Quotient
Blog/How to Report Cyber Attacks in Malaysia: A Guide for Organizations
Cyber Security Awareness

How to Report Cyber Attacks in Malaysia: A Guide for Organizations

Learn how organizations in Malaysia can report cyber attacks, understand regulatory requirements, and respond effectively to security incidents.

Featured Image
Sreelakshmi M PĀ·Ā·5 min read

Cyber threats are on the rise in Malaysia, with many businesses becoming targets of cyber attacks. No matter how strong the measures, these threats are always lurking, waiting for a moment to strike. As soon as a cyber incident is reported within an organization, the first priority of leadership is to act quickly and responsibly. Immediate steps should be taken to assess the situation, verify the threat, and contain the incident according to the organization’s incident response plan. This initial response is vital for minimizing damage and stopping the attack from spreading. The faster an organization can contain the incident internally, the less damage it is likely to cause to operations and reputation.

Once the internal response is underway, it is the responsibility of the organization’s leadership to report the incident to the relevant authorities and stakeholders. The decision on where and whom to report to depends on factors such as the nature and severity of the incident, as well as the sector involved. Taking the right steps to report the attack ensures proper investigation, strengthens the overall cyber security effort, and helps prevent similar attacks in the future. This article will explore the essential steps involved in reporting a cyber attack in Malaysia and highlight the importance of acting responsibly in the aftermath of an incident.

When and How to Report Cyber Attacks After Internal Incident Response?

Below is a list of key parties to whom such incidents should be reported and when to report them:

1. Inform Affected Parties

Notifying affected parties, such as customers, employees, or partners, is a high priority because they have the ultimate right to know, especially if their data has been breached. The sooner they are informed, the sooner they can take action to protect themselves, such as changing passwords, monitoring accounts for suspicious activity, or taking extra security measures. Clear and timely communication is crucial because, in the case of a data breach, there is a high chance their information could be misused for targeted attacks. Transparency helps mitigate concerns, maintain trust, and allows those affected to take the necessary steps to protect themselves.

2. Report to CyberSecurity Malaysia (CSM)

CyberSecurity Malaysia, the national cyber security specialist agency under the purview of the Ministry of Digital, plays a critical role in managing and responding to cyber incidents, serving as the main point of contact for reporting such events.Ā MyCERTĀ (Malaysian Computer Emergency Response Team) is a government initiative under CyberSecurity Malaysia. As the national cyber emergency response team, MyCERT is responsible for monitoring, managing, and responding to cyber threats and incidents in Malaysia. It operates theĀ Cyber999Ā service, which serves as the official point of contact for reporting cyber security incidents. It provides immediate response to assist Malaysian Internet users in addressing and resolving these incidents.

When to report: All cyber incidents, including phishing, malware infections, unauthorized access, and denial-of-service attacks, should be reported promptly.

How to report: Cyber999 provides several channels for reporting cyber incidents, including anĀ online form, email, phone calls, and the Cyber999 mobile app, making it accessible for users to report security issues promptly.

  • Phone Call – For emergency incidents, you can contact Cyber999 through the hotline at 1-300-88-2999. For 24/7 assistance, MyCERT can be reached at +6019-266 5850. Please note that calls to MyCERT and the Cyber999 hotline are monitored during business hours, from 8:30 AM to 5:30 PM.
  • Email – Security incidents can be reported to MyCERT by sending an email toĀ cyber999 [at] cybersecurity.my

To effectively report a cyber attack, it is good to include the following information or artifacts, if available: the source and destination of the attack, the email header, relevant log files, and the time of the attack. These details will aid in the investigation and response process.

3. Reporting to the National Cyber Security Agency (NACSA)

TheĀ National Cyber Security Agency (NACSA)Ā was officially established in February 2017 as the national lead agency for cyber security matters. Its objectives include securing Malaysia’s National Critical Information Infrastructures (NCII), developing and implementing national cyber security policies, and strengthening the nation’s resilience against cyber threats. National Critical Information Infrastructures (NCII) refer to essential computer resources, the disruption of which would have a significant impact on national security, the economy, or public welfare.

When to report: If the cyber incident affects national critical information infrastructure (NCII) or poses a threat to national security.

How to report: To report an incident to the National Cyber Security Agency (NACSA), you can use the incident reporting form availableĀ here.

4. File a Police Report

The Royal Malaysia Police (PDRM) is the centralized national and federal police force in Malaysia, responsible for maintaining law and order across the country. PDRM has a specialized Cyber Crime Unit that investigates cyber-related criminal activities. Reporting a cyber attack to PDRM is crucial for initiating an official investigation, addressing the criminal aspects of the attack, and ensuring the proper legal actions are taken. This report also serves to document the crime for future legal proceedings.

When to report: If the cyber attack involves criminal activities such as data theft, financial fraud, or unauthorized access.

How to report: You can file a report at the nearest police station or through theĀ PDRM’s online portal.

5. Report Personal Data Breaches

The Personal Data Protection Act 2010 (PDPA) in Malaysia came into effect on November 15, 2013. This comprehensive law regulates the handling of personal data by individuals and organizations, ensuring the privacy and digital rights of the individuals.

When to report: If the cyber attack compromises personal data, organizations are required to notify theĀ Personal Data Protection Commissioner (PDP)Ā under theĀ Personal Data Protection Act (PDPA). Organizations must inform the PDP withinĀ 72 hoursĀ of discovering a breach. This step ensures that the proper steps are taken to mitigate the breach and safeguard affected individuals’ data.

How to report: Personal data breaches can be reported through the officialĀ PDP portalĀ or via email.

6. Notify Sector-Specific Regulators

Depending on the nature of the cyber attack and the sector involved, it is advisable to report the incident to the relevantĀ sector-specific regulators. This ensures that the appropriate authorities are informed and can take necessary actions to address the incident within their respective sectors. Reporting to the right regulatory body can help facilitate a more coordinated response and mitigate potential sector-wide risks.

For instance, theĀ Securities Commission of MalaysiaĀ requires capital market entities to report any cyber incidents affecting their information assets or systems to the Commission. Similarly, financial service providers are subject to a strict regulatory framework established byĀ Bank Negara Malaysia (BNM).

Turning Hesitation Into Action

Many may hesitate to report cyber incidents promptly, weighed down by concerns over reputation, legal complications, or potential fallout. However, before getting caught up in these worries, it’s important to remember that prompt reporting plays a critical role in improving incident response plans and enhancing security strategies. Not only does this protect the individual or organization involved, but it also benefits the broader community. Every reported incident contributes to the collective cyber security knowledge, helping everyone learn from past experiences. The lessons learned can be leveraged to better prepare for future threats, ultimately fostering progress in the fight against cyber crime.

Frequently Asked Questions

How does this training mitigate human error and build cyber resilience? ā–¼

Human error remains the leading cause of security incidents. We move beyond theoretical compliance to focus on behavioral change. By drawing on over two decades of experience in cybersecurity and compliance training, we provide actionable, everyday best practices. Employees learn exactly how to verify secure communications, identify malicious links, handle sensitive files safely, and respond decisively to potential threats.

What are the top cyber threats currently facing Malaysia businesses? ā–¼

Malaysia remains a high-traffic target for cybercriminals in Southeast Asia. Top threats for 2026 include:

  • AI-Powered Phishing: Sophisticated, localized social engineering attacks (sometimes using "Manglish" or specific local context) to bypass traditional email filters.
  • Ransomware-as-a-Service (RaaS): Targeted attacks on Malaysian SMEs and supply chains, where data is stolen and encrypted for high ransom demands.
  • QR Code Scams ("Quishing"): Exploiting Malaysia's high adoption of QR payments to redirect users to malicious phishing sites.
  • Business Email Compromise (BEC): Impersonating vendors or executives to divert corporate payments to fraudulent accounts.
What are the top cyber threats currently facing Singapore businesses? ā–¼

Organizations in Singapore are increasingly targeted by sophisticated, localized attacks. The most prominent threats include AI-driven phishing campaigns, Business Email Compromise (BEC) targeting finance and vendor communications, and Ransomware-as-a-Service (RaaS) operations. Our training directly addresses these modern vectors, teaching employees how to recognize the subtle red flags of advanced social engineering.

What are the top cyber threats currently facing Indian businesses? ā–¼

India is currently one of the most targeted regions for cyber warfare and financial crime. Key threats in the 2026 landscape include:

  • AI-Enhanced Phishing: Hyper-personalized social engineering attacks using Deepfakes and AI-generated scripts to target finance and HR departments.
  • Double-Extortion Ransomware: Where attackers not only lock systems but also threaten to leak sensitive data, triggering immediate DPDP Act penalties.
  • Supply Chain Attacks: Exploiting vulnerabilities in third-party vendors to gain access to the primary organization’s data.
  • Credential Harvesting: Targeted attacks on employee login portals to bypass traditional perimeter security.
Do SMEs need to outsource their cyber security compliance needs?ā–¼

Yes, SMEs can outsource their cyber security compliance needs if resources allow. Outsourcing provides access to expert knowledge, improves efficiency, and reduces the costs associated with hiring a full-time, in-house compliance team. It also enables SMEs to focus on their core business operations while ensuring compliance is handled by specialists.

Request a demo

Reduce human cyber and compliance risks with targeted training.
Get a guided walkthrough — at a time that suits your timezone.

Request a demo →