BNM Fined Bank Rakyat RM1 Million Over Cybersecurity Breaches

KUALA LUMPUR, Jan 26 — Bank Negara has imposed a RM1 million administrative monetary penalty on entity-accent entity-underline inline cursor-pointer align-baseline Bank Kerjasama Rakyat Malaysia Berhad(Bank Rakyat) for failing to meet required cybersecurity and customer data protection standards. The central bank said the penalty, imposed on Jan 20, 2026, followed the discovery of multiple breaches under its Risk Management in Technology Policy Document (RMiT PD) and Management of Customer Information and Permitted Disclosures Policy Document (MCIPD PD). The violations were uncovered after a cybersecurity incident in which an external threat actor gained unauthorised access to the bank’s IT infrastructure. Investigations found that the breaches stemmed from inadequate cybersecurity controls and weaknesses in incident response. BNM said Bank Rakyat failed to implement robust cybersecurity measures and did not sufficiently safeguard customer information as required under regulatory guidelines. The bank has since taken remedial steps to strengthen its cybersecurity framework, including improvements to its information and communication technology (ICT) controls, resources and governance. In determining the penalty, BNM considered several factors, including the severity of the breaches, the bank’s lack of reasonable care in ensuring compliance, its existing control environment, past compliance record, and actions taken after the incident to prevent recurrence. Bank Rakyat paid the RM1 million penalty on Jan 26, 2026. BNM reiterated that all financial institutions must comply with its technology risk management and customer information policies, warning that it will take firm supervisory and enforcement action against any institution that fails to meet regulatory requirements.

KUALA LUMPUR — Bank Negara has imposed a RM1 million administrative monetary penalty on Bank Kerjasama Rakyat Malaysia Berhad(Bank Rakyat) for failing to meet required cybersecurity and customer data protection standards. The central bank said the penalty, imposed on Jan 20, 2026, followed the discovery of multiple breaches under its Risk Management in Technology Policy […]