Computer Crimes Act 1997, unauthorised access to computer material
Computer Crimes Act 1997 (Act 563), s. 3 (Unauthorised Access to Computer Material)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 June 2000.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not cause a computer to perform a function to secure access to a program or data where that access is unauthorised and you know it to be unauthorised.
- Reading a public, unauthenticated page without defeating any access control falls outside a plain reading of this section, though no reported Malaysian decision addresses the point either way.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A fine not exceeding fifty thousand ringgit or imprisonment not exceeding five years, or both, on conviction (s. 3(3)); higher penalties apply under s. 4 (up to RM150,000 or ten years) for unauthorised access committed with intent to commit or facilitate fraud or an offence causing injury, and under s. 5 (up to RM100,000 or seven years, rising to RM150,000 or ten years where done with intent to cause injury as defined in the Penal Code) for unauthorised modification of the contents of a computer.
Penalty structure
Section 3 fine only; the same subsection also allows imprisonment of up to five years instead of or in addition to the fine. Sections 4 and 5 carry separate, higher fixed caps (up to RM150,000) for aggravated unauthorised access and unauthorised modification, not reflected in this cap.
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- MYR
- Fixed cap
- 50,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 3 makes it an offence to cause a computer to perform a function with intent to secure access to a program or data held in any computer, where that access is unauthorised and the person knows at the time that it is unauthorised; the intent need not be directed at any particular program, data, or computer.
Section 2(5) defines access as unauthorised only where the person is not entitled to control access of that kind and does not have consent from, or exceeds a right or consent given by, a person who is so entitled.
Because the offence turns on whether the access itself is unauthorised rather than on the manner of access, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision, though no reported Malaysian decision addresses the point either way.
Sections 4 and 5 separately punish, at higher penalties, unauthorised access committed with intent to commit or facilitate a further offence, and unauthorised modification of the contents of a computer.
When LexLint raises it
crawls_webtrains_models