How to Report Cyber Attacks in Malaysia: A Guide for Organizations
Learn how organizations in Malaysia can report cyber attacks, understand regulatory requirements, and respond effectively to security incidents.

Cyber threats are on the rise in Malaysia, with many businesses becoming targets of cyber attacks. No matter how strong the measures, these threats are always lurking, waiting for a moment to strike. As soon as a cyber incident is reported within an organization, the first priority of leadership is to act quickly and responsibly. Immediate steps should be taken to assess the situation, verify the threat, and contain the incident according to the organizationās incident response plan. This initial response is vital for minimizing damage and stopping the attack from spreading. The faster an organization can contain the incident internally, the less damage it is likely to cause to operations and reputation.
Once the internal response is underway, it is the responsibility of the organizationās leadership to report the incident to the relevant authorities and stakeholders. The decision on where and whom to report to depends on factors such as the nature and severity of the incident, as well as the sector involved. Taking the right steps to report the attack ensures proper investigation, strengthens the overall cyber security effort, and helps prevent similar attacks in the future. This article will explore the essential steps involved in reporting a cyber attack in Malaysia and highlight the importance of acting responsibly in the aftermath of an incident.
When and How to Report Cyber Attacks After Internal Incident Response?
Below is a list of key parties to whom such incidents should be reported and when to report them:
1. Inform Affected Parties
Notifying affected parties, such as customers, employees, or partners, is a high priority because they have the ultimate right to know, especially if their data has been breached. The sooner they are informed, the sooner they can take action to protect themselves, such as changing passwords, monitoring accounts for suspicious activity, or taking extra security measures. Clear and timely communication is crucial because, in the case of a data breach, there is a high chance their information could be misused for targeted attacks. Transparency helps mitigate concerns, maintain trust, and allows those affected to take the necessary steps to protect themselves.
2. Report to CyberSecurity Malaysia (CSM)
CyberSecurity Malaysia, the national cyber security specialist agency under the purview of the Ministry of Digital, plays a critical role in managing and responding to cyber incidents, serving as the main point of contact for reporting such events.Ā MyCERTĀ (Malaysian Computer Emergency Response Team) is a government initiative under CyberSecurity Malaysia. As the national cyber emergency response team, MyCERT is responsible for monitoring, managing, and responding to cyber threats and incidents in Malaysia. It operates theĀ Cyber999Ā service, which serves as the official point of contact for reporting cyber security incidents. It provides immediate response to assist Malaysian Internet users in addressing and resolving these incidents.
When to report: All cyber incidents, including phishing, malware infections, unauthorized access, and denial-of-service attacks, should be reported promptly.
How to report: Cyber999 provides several channels for reporting cyber incidents, including anĀ online form, email, phone calls, and the Cyber999 mobile app, making it accessible for users to report security issues promptly.
- Phone CallĀ ā For emergency incidents, you can contact Cyber999 through the hotline at 1-300-88-2999. For 24/7 assistance, MyCERT can be reached at +6019-266 5850. Please note that calls to MyCERT and the Cyber999 hotline are monitored during business hours, from 8:30 AM to 5:30 PM.
- EmailĀ ā Security incidents can be reported to MyCERT by sending an email toĀ cyber999 [at] cybersecurity.my
To effectively report a cyber attack, it is good to include the following information or artifacts, if available: the source and destination of the attack, the email header, relevant log files, and the time of the attack. These details will aid in the investigation and response process.
3. Reporting to the National Cyber Security Agency (NACSA)
TheĀ National Cyber Security Agency (NACSA)Ā was officially established in February 2017 as the national lead agency for cyber security matters. Its objectives include securing Malaysiaās National Critical Information Infrastructures (NCII), developing and implementing national cyber security policies, and strengthening the nationās resilience against cyber threats. National Critical Information Infrastructures (NCII) refer to essential computer resources, the disruption of which would have a significant impact on national security, the economy, or public welfare.
When to report: If the cyber incident affects national critical information infrastructure (NCII) or poses a threat to national security.
How to report: To report an incident to the National Cyber Security Agency (NACSA), you can use the incident reporting form availableĀ here.
4. File a Police Report
The Royal Malaysia Police (PDRM) is the centralized national and federal police force in Malaysia, responsible for maintaining law and order across the country. PDRM has a specialized Cyber Crime Unit that investigates cyber-related criminal activities. Reporting a cyber attack to PDRM is crucial for initiating an official investigation, addressing the criminal aspects of the attack, and ensuring the proper legal actions are taken. This report also serves to document the crime for future legal proceedings.
When to report: If the cyber attack involves criminal activities such as data theft, financial fraud, or unauthorized access.
How to report: You can file a report at the nearest police station or through theĀ PDRMās online portal.
5. Report Personal Data Breaches
The Personal Data Protection Act 2010 (PDPA) in Malaysia came into effect on November 15, 2013. This comprehensive law regulates the handling of personal data by individuals and organizations, ensuring the privacy and digital rights of the individuals.
When to report: If the cyber attack compromises personal data, organizations are required to notify theĀ Personal Data Protection Commissioner (PDP)Ā under theĀ Personal Data Protection Act (PDPA). Organizations must inform the PDP withinĀ 72 hoursĀ of discovering a breach. This step ensures that the proper steps are taken to mitigate the breach and safeguard affected individualsā data.
How to report: Personal data breaches can be reported through the officialĀ PDP portalĀ or via email.
6. Notify Sector-Specific Regulators
Depending on the nature of the cyber attack and the sector involved, it is advisable to report the incident to the relevantĀ sector-specific regulators. This ensures that the appropriate authorities are informed and can take necessary actions to address the incident within their respective sectors. Reporting to the right regulatory body can help facilitate a more coordinated response and mitigate potential sector-wide risks.
For instance, theĀ Securities Commission of MalaysiaĀ requires capital market entities to report any cyber incidents affecting their information assets or systems to the Commission. Similarly, financial service providers are subject to a strict regulatory framework established byĀ Bank Negara Malaysia (BNM).
Turning Hesitation Into Action
Many may hesitate to report cyber incidents promptly, weighed down by concerns over reputation, legal complications, or potential fallout. However, before getting caught up in these worries, itās important to remember that prompt reporting plays a critical role in improving incident response plans and enhancing security strategies. Not only does this protect the individual or organization involved, but it also benefits the broader community. Every reported incident contributes to the collective cyber security knowledge, helping everyone learn from past experiences. The lessons learned can be leveraged to better prepare for future threats, ultimately fostering progress in the fight against cyber crime.
Recommended Courses

Security Awareness Course Ā· Malaysia Edition
Security awareness training that equips your workforce, through local case studies, to stop sophisticated phishing, spot deepfakes, and build safe-AI skills ā aligned with the PDPA and BNM RMiT guidelines.
View Course ā
Security Awareness Course Ā· Singapore Edition
Through real-world case studies, prepare your workforce to stop sophisticated phishing, detect deepfakes, and apply safe-AI skills ā aligned with the PDPA and MAS TRM guidelines.
View Course ā
AI Governance Training Ā· Global Edition
Equip your workforce to manage AI risk, bias, and accountability across the full lifecycle ā with practical, scenario-based training aligned to the EU AI Act and ISO 42001.
View Course āFrequently Asked Questions
How does this training mitigate human error and build cyber resilience? ā¼
Human error remains the leading cause of security incidents. We move beyond theoretical compliance to focus on behavioral change. By drawing on over two decades of experience in cybersecurity and compliance training, we provide actionable, everyday best practices. Employees learn exactly how to verify secure communications, identify malicious links, handle sensitive files safely, and respond decisively to potential threats.
What are the top cyber threats currently facing Malaysia businesses? ā¼
Malaysia remains a high-traffic target for cybercriminals in Southeast Asia. Top threats for 2026 include:
- AI-Powered Phishing: Sophisticated, localized social engineering attacks (sometimes using "Manglish" or specific local context) to bypass traditional email filters.
- Ransomware-as-a-Service (RaaS): Targeted attacks on Malaysian SMEs and supply chains, where data is stolen and encrypted for high ransom demands.
- QR Code Scams ("Quishing"): Exploiting Malaysia's high adoption of QR payments to redirect users to malicious phishing sites.
- Business Email Compromise (BEC): Impersonating vendors or executives to divert corporate payments to fraudulent accounts.
What are the top cyber threats currently facing Singapore businesses? ā¼
Organizations in Singapore are increasingly targeted by sophisticated, localized attacks. The most prominent threats include AI-driven phishing campaigns, Business Email Compromise (BEC) targeting finance and vendor communications, and Ransomware-as-a-Service (RaaS) operations. Our training directly addresses these modern vectors, teaching employees how to recognize the subtle red flags of advanced social engineering.
What are the top cyber threats currently facing Indian businesses? ā¼
India is currently one of the most targeted regions for cyber warfare and financial crime. Key threats in the 2026 landscape include:
- AI-Enhanced Phishing: Hyper-personalized social engineering attacks using Deepfakes and AI-generated scripts to target finance and HR departments.
- Double-Extortion Ransomware: Where attackers not only lock systems but also threaten to leak sensitive data, triggering immediate DPDP Act penalties.
- Supply Chain Attacks: Exploiting vulnerabilities in third-party vendors to gain access to the primary organizationās data.
- Credential Harvesting: Targeted attacks on employee login portals to bypass traditional perimeter security.
Do SMEs need to outsource their cyber security compliance needs?ā¼
Yes, SMEs can outsource their cyber security compliance needs if resources allow. Outsourcing provides access to expert knowledge, improves efficiency, and reduces the costs associated with hiring a full-time, in-house compliance team. It also enables SMEs to focus on their core business operations while ensuring compliance is handled by specialists.
Request a demo
Reduce human cyber and compliance risks with targeted training.
Get a guided walkthrough ā at a time that suits your timezone.