Sri Lanka’s banking sector is entering a dangerous new phase: its financial foundations remain resilient, but the rapid digital transformation of banking is exposing vulnerabilities that traditional balance-sheet indicators cannot measure.

The Central Bank of Sri Lanka (CBSL) reports that private-sector credit accelerated through 2025 and the first quarter of 2026, challenging fears that slower expansion of physical retail banking would weaken the industry.
However that growth has coincided with an unprecedented surge in digital fraud, cybersecurity complaints and internal banking risks. More than 12,650 cybersecurity incidents were formally recorded, representing a 134% increase, while security authorities estimate the true annual number of scams could range from 38,000 to 63,000.
The scale of the threat became impossible to ignore in April, when National Development Bank PLC disclosed an internal fraud that grew from an initial estimate of LKR 380 million to LKR 13.2 billion. Separately, international criminal networks reportedly diverted a USD 2.5 million government foreign-debt repayment by infiltrating email systems.
The methods now confronting banks are also becoming more sophisticated. Criminals are deploying malicious smartphone APK files, synthetic identities and highly convincing replicas of local bank websites. Fraudsters are even exploiting Google search advertising to steer customers toward cloned banking portals designed to capture usernames and one-time passwords. More advanced operations increasingly incorporate artificial intelligence and automated scam platforms.
Authorities are also confronting transnational networks that have shifted operations into Sri Lanka following enforcement pressure in Cambodia and Thailand. The country’s connectivity and expanding digital economy have created opportunities not only for legitimate businesses, but potentially for organized cybercrime.
Hitherto the banking system itself is not showing signs of imminent systemic collapse. Capital and liquidity remain above regulatory requirements for most commercial banks, while non-performing loan indicators have generally improved from post-crisis highs. Commercial Bank of Ceylon, Hatton National Bank and Sampath Bank remain among institutions with comparatively strong capital positions.
The pressure is instead emerging where rapid lending, technology and operational controls intersect. Before its fraud losses, NDB’s loans had reportedly grown 26.7%, compared with deposit growth of 10.4%, putting additional pressure on capital buffers. Meanwhile, CBSL tightened monetary policy in May 2026, moderating banks’ appetite for new lending during the second quarter.
Regulators are now moving beyond warnings. New cybersecurity requirements require banks to conduct independent data audits, undertake realistic cyberattack simulations and report cyber threats and online scams directly to CBSL. The Financial Intelligence Unit has also imposed LKR 14.6 million in penalties on 11 institutions for breaches of financial-reporting requirements.
The banking sector’s proposed 20-point cyber-resilience framework could become the next crucial test. Its emphasis on AI-driven surveillance and early anomaly detection signals a fundamental shift: protecting Sri Lanka’s banking system may now depend as much on detecting fraud inside and outside the institution as on maintaining capital ratios.
The central question is no longer whether Sri Lanka’s banks can survive financial shocks.



