Dr. Shariful Haque Priom
A major cyber fraud incident has shaken Sri Lanka after hackers infiltrated a government email system and successfully diverted about $2.5 million in public funds meant for foreign debt repayment. The breach, which targeted the country’s central financial operations, has triggered political outrage, raised concerns about institutional accountability, and exposed serious weaknesses in state digital security.
According to officials, the cyberattack compromised the email system of the Treasury’s Public Debt Management Office, a unit responsible for handling external debt obligations. By gaining access to official communication channels, the attackers were able to impersonate legitimate stakeholders and manipulate payment instructions. The funds-intended for an Australian export finance agency-were instead redirected to accounts controlled by the cybercriminals.
The fraudulent transfers took place over several months, from December 31, 2025, to March 20, 2026, and were carried out in five separate payments. Alarmingly, the breach went unnoticed during that time. It was only when the intended recipient in Australia informed Sri Lankan authorities that the money had not been received that the fraud was discovered.
Treasury Secretary Harshana Suriyapperuma confirmed the incident publicly, stating that while all required procedures had been followed internally, the funds were still diverted. “Although the government followed the required procedures and completed the payment, the intended recipient did not receive the money,” he said. “Instead, criminals who interfered in the email communications were able to redirect nearly $2.5 million into other accounts.”
The disclosure has sparked strong criticism from opposition leaders and transparency advocates, who argue that the incident reflects not only a technical failure but also a wider breakdown in governance and oversight. The Sri Lankan branch of Transparency International described the breach as a “serious lapse of financial oversight,” warning that such weaknesses can damage public trust and fiscal discipline.
Opposition lawmaker Harsha de Silva, a key member of the Samagi Jana Balawegaya alliance and head of the parliamentary Committee on Public Finance, strongly criticized the government’s handling of the situation. He accused authorities of withholding information from Parliament and undermining constitutional oversight of public finances. “In over 15 years in Parliament, I have never seen this level of disregard for parliamentary oversight,” he said in a public statement.
The government has defended its decision to delay disclosure. Suriyapperuma argued that early public release of information could have harmed the ongoing investigation and made it harder to track and recover the stolen funds. He confirmed that several finance officials have been suspended while the investigation continues, although details about their roles or possible responsibility have not yet been made public.
Cybersecurity experts say the incident has the characteristics of a Business Email Compromise (BEC) attack, a type of cybercrime that targets organizations involved in high-value financial transactions. In such attacks, criminals either gain access to real email accounts or create convincing fake ones, monitor communication patterns, and intervene at critical moments to change payment details. These schemes rely heavily on deception and human error rather than advanced technical methods.
The case in Sri Lanka shows how even established financial systems can be vulnerable if proper safeguards are not in place. Experts stress the importance of measures such as multi-factor authentication, secure communication systems, and independent verification of payment instructions, especially for international transfers. Without these protections, even routine financial operations can become targets for fraud.
The financial impact of the incident is serious, especially for a country like Sri Lanka, which has faced economic difficulties and debt challenges in recent years. Although $2.5 million is a relatively small amount compared to the country’s total debt, the damage to its reputation and the possible effect on lender confidence could be much more significant. International partners may now seek stronger guarantees about the safety and transparency of financial transactions.
Politically, the incident has increased tensions between the government and the opposition. Calls for an independent investigation are growing, with critics insisting that any inquiry must be transparent and free from political influence. There are also demands for a broader review of digital systems across government institutions to identify and fix weaknesses.
The incident also reflects a wider global pattern in which public institutions are increasingly targeted by cybercriminals. Governments manage large amounts of sensitive information and financial resources, making them attractive targets. However, many public sector systems are not as well protected as those in the private sector, leaving them exposed to modern cyber threats.
For Sri Lanka, the response will likely involve both immediate and long-term actions. In the short term, efforts will focus on tracing the stolen funds, working with international partners, and strengthening internal controls. In the long term, the government may need to invest more in cybersecurity infrastructure, employee training, and stronger regulations to prevent similar incidents.
This case is a clear reminder that in today’s digital world, financial security depends heavily on cybersecurity. As investigations continue, the incident will serve as an important test of Sri Lanka’s ability to ensure transparency, strengthen its institutions, and protect public funds from increasingly sophisticated cyber threats.
Leave a Reply