Sri Lanka’s financial system suffered a sophisticated cyber-attack that exposed not only weaknesses in government technology, but also serious failures in institutional oversight during a critical transition in sovereign debt management.

According to the investigation findings provided, hackers infiltrated the Finance Ministry’s External Resources Department (ERD) in early 2026 using look-alike domains designed to hijack legitimate email conversations. The attackers redirected five bilateral debt repayment installments intended for the Australian government, causing losses estimated at US$2.5 million.
The breach was made possible by basic cyber security weaknesses that investigators found difficult to justify. The ERD was reportedly still operating a 2016 Microsoft Exchange email server after official technical support had expired. Security updates had ceased one month before the attack, while Multi-Factor Authentication was not deployed.
More significantly, the vulnerabilities were reportedly known before the theft occurred. Written warnings from KPMG and the Sri Lanka Computer Emergency Readiness Team had highlighted the security risks. Despite those warnings, the necessary corrective action was not taken by Treasury leadership.
The attack also coincided with a major institutional transition. Responsibility for debt management was moving from the Central Bank of Sri Lanka to the newly established Public Debt Management Office. Investigators identified the handover as a potential operational blind spot, with responsibilities, systems and security controls vulnerable to gaps during the transition.
The attempted fraud did not end with the Australian payments. Similar fraudulent redirections were reportedly attempted against debt repayments involving India, the United Kingdom, Germany and Belgium. Those transactions were detected and blocked, limiting the financial damage.
The episode highlights a broader problem: sophisticated criminals did not need to defeat advanced government security systems. Instead, they exploited weaknesses that should have been addressed through routine controls, including updated software, authenticated government email and stronger transaction verification.
The remedial framework outlined in the investigation calls for immediate decommissioning of unsupported government servers and mandatory Multi-Factor Authentication across state financial networks. Treasury and PDMO communications and data are also expected to move into a secure, monitored government cloud environment.
Email authentication standards, including SPF, DKIM and DMARC, are to be enforced to combat domain spoofing. Financial officers will also be prohibited from changing beneficiary or routing information solely on the basis of email instructions.
The proposed safeguards introduce another layer of protection: high-value sovereign payments will require split authorization, while approved beneficiary accounts will be maintained in a centralized cryptographic database.
The central lesson is stark. Sri Lanka’s fiscal security depends not only on defending against sophisticated criminals, but on eliminating institutional weaknesses that allow preventable attacks to succeed.



