Latest Posts

Treasury Cyber Heist Exposes Shocking Governance Collapse at Highest Levels

Sri Lanka’s US$2.5 million Treasury cyber heist has evolved from a sophisticated international cybercrime into one of the country’s most damning governance failures, with Parliament’s Committee on Public Finance (COPF) laying bare systemic negligence that enabled public funds to be stolen through a preventable security breach.

The committee’s exhaustive 169-page report and its unanimous supplementary report stop short of assigning criminal liability to senior officials but make it unmistakably clear that institutional responsibility reaches the highest levels of the Ministry of Finance and the Central Bank of Sri Lanka.

Far from exonerating the Secretary to the Treasury, the Governor of the Central Bank or other senior officials, COPF states that determining criminal intent or collusion falls exclusively within the jurisdiction of law enforcement agencies, including the Criminal Investigation Department. Parliament’s responsibility, Chairman Dr. Harsha de Silva stressed, was to determine how public funds were lost and identify governance failures that made the theft possible.

The findings paint a disturbing picture of an institution operating with dangerously outdated technology. Treasury operations reportedly relied on an obsolete Microsoft Exchange email server that had been unsupported since 2019, lacked even basic multi-factor authentication, and functioned without adequate cyber security safeguards. Investigators concluded these weaknesses created an ideal environment for cybercriminals to infiltrate payment systems unnoticed.

The report further reveals that the External Resources Department was permitted to operate an isolated server outside the Treasury’s central network during the transition of sovereign debt management responsibilities from the Central Bank to the newly established Public Debt Management Office. According to COPF, this poorly managed restructuring created the precise vulnerability exploited by hackers.

The fraud first surfaced only after JP Morgan’s global fraud detection systems flagged a suspicious payment intended for India’s Axis Bank. Further investigations uncovered attempts to redirect additional sovereign debt payments destined for financial institutions in the United Kingdom, Germany and Belgium, indicating the breach was neither isolated nor accidental.

Parliament also criticised what it described as bureaucratic finger-pointing between the Treasury and the Central Bank instead of coordinated efforts to address mounting cyber security risks. While legal advice argued that operational responsibility had shifted to the Public Debt Management Office, COPF concluded that the Central Bank could not entirely distance itself from responsibility for supervising systemic risks within Sri Lanka’s foreign debt payment framework.

Perhaps most controversially, the reports note that although governance failures occurred at the highest administrative levels, only four mid-level Finance Ministry officials were suspended in the immediate aftermath. This disparity has fuelled renewed public debate over whether accountability has disproportionately fallen on junior officials while senior decision-makers remain insulated.

The committee also documents instances where scheduled parliamentary hearings were delayed amid requests from senior Treasury officials, further intensifying scrutiny over transparency during the investigation.

With criminal investigations continuing, COPF’s findings have shifted the national conversation beyond a cyber attack to deeper questions about institutional accountability, leadership failures and whether Sri Lanka’s financial governance systems were left dangerously exposed long before hackers struck.

By a Special Correspondent

Latest Posts

spot_imgspot_img