Kuala lumpur: Bank Negara Malaysia (BNM) has imposed an administrative monetary penalty (AMP) of RM1 million on Bank Kerjasama Rakyat Malaysia Bhd (Bank Rakyat) for cybersecurity and customer information protection breaches on Jan 20, 2026.
According to BERNAMA News Agency, the central bank stated that Bank Rakyat did not implement robust cybersecurity standards as mandated under the risk management in technology policy document (RMiT PD). Furthermore, the bank failed to safeguard customer information through adequate controls as required by the management of customer information and permitted disclosures policy document (MCIPD PD).
BNM discovered that Bank Rakyat had breached several requirements under the RMiT PD and MCIPD PD following a cybersecurity incident where an external threat actor gained unauthorised access to its information technology (IT) infrastructure. The central bank attributed these breaches to inadequate cybersecurity controls and incident response.
The central bank noted that Bank Rakyat has since taken remedial measures to enhance its cybersecurity and information and communication technology (ICT) controls, resources, and governance arrangements. In determining the AMP, BNM considered various aggravating and mitigating factors, including the severity of the breaches, Bank Rakyat's lack of reasonable care in ensuring compliance, current compliance controls, past compliance record, and the effectiveness of remedial actions to prevent recurrence.
Bank Rakyat paid the RM1 million penalty on Jan 26, 2026. BNM emphasized that all financial institutions are required to comply with the RMiT PD and MCIPD PD and warned that it will not hesitate to take appropriate supervisory and enforcement actions for non-compliance. The enforcement action against Bank Rakyat aligns with BNM's published Enforcement Approach.