Bank Rakyat Fined RM1 Million for Cybersecurity Breaches
Severity: Medium (Score: 48.9)
Sources: Freemalaysiatoday, Theedgemalaysia, Thevibes
Summary
Bank Negara Malaysia (BNM) fined Bank Rakyat RM1 million on January 20, 2026, due to breaches in cybersecurity and customer data protection. The breaches were attributed to inadequate cybersecurity controls and incident response, which allowed an external threat actor unauthorized access to Bank Rakyat's IT infrastructure. The central bank stated that the severity of the breaches and the bank's lack of reasonable care in compliance were significant factors in determining the penalty. Bank Rakyat paid the fine on January 26, 2026, and has since implemented remedial measures to enhance its cybersecurity and governance arrangements. BNM emphasized its commitment to enforcing compliance among financial institutions to protect customer data. The incident highlights ongoing vulnerabilities within financial institutions in Malaysia. Key Points: • Bank Rakyat fined RM1 million for cybersecurity breaches on January 20, 2026. • Inadequate cybersecurity controls allowed unauthorized access to Bank Rakyat's IT systems. • Remedial measures have been implemented to strengthen cybersecurity post-incident.
Key Entities
- Data Breach (attack_type)
- Bank Kerjasama Rakyat Malaysia Bhd (company)
- Bank Rakyat (company)
- Malaysia (country)
- Financial (industry)