Latest Posts

US $2.5 Million Treasury Cyber Heist Exposes Dangerous State Security Gaps

Sri Lanka’s biggest known digital theft from a state institution has exposed a chain of technological, procedural and institutional failures at the heart of the country’s sovereign debt payment machinery, raising questions far beyond the relatively modest US$2.5 million that disappeared.

The ongoing investigation has established that hackers manipulated email-based payment instructions and diverted funds in five tranches between December 2025 and January 2026. The money formed part of a US$22.9 million bilateral debt repayment due to Export Finance Australia. The fraud came to light only after the Australian creditor reported that the expected payment had not arrived.

The scale of the loss is significant less for its immediate impact on reserves than for what it reveals about the security architecture governing billions of dollars of sovereign transactions.

The Parliamentary Committee on Public Finance (COPF) identified weak email infrastructure and inadequate standard operating procedures during the transition to the newly established Public Debt Management Office (PDMO) as central vulnerabilities.

More troublingly, the External Resources Department had reportedly continued using a 2016 Microsoft Exchange email server without multi-factor authentication. Previous warnings from Sri Lanka CERT and KPMG had apparently failed to produce an adequate corrective response.

That failure created an opening for criminals to impersonate or manipulate legitimate payment instructions.

The danger became even clearer when an attempted manipulation involving a payment to India was subsequently detected and stopped.

Four senior PDMO officers have since been interdicted and suspended while the Criminal Investigation Department investigates the circumstances. The death of an Assistant Director of the ERD, who had been interdicted and questioned twice by the CID before being found dead at his home in July, has added another deeply troubling dimension to the investigation. The circumstances surrounding that death must be established independently rather than allowing speculation to substitute for evidence.

Meanwhile, investigators are following an international money trail. Digital forensic evidence indicates that the stolen funds were routed through fraudulent accounts in Delaware and trade-related entities in Dubai. Mutual Legal Assistance requests have been sent to the United States, United Arab Emirates, Switzerland, Australia and Zambia.

The Australian Federal Police is also assisting Sri Lankan authorities by sharing relevant server data and access logs.

The theft has already created institutional consequences. The Treasury temporarily froze and manually audited recent high-value external transfers, increasing administrative friction and slowing foreign currency transactions.

There was also a potential international credibility cost. Because the Australian payment failed to reach its destination, Sri Lanka technically breached the IMF Extended Fund Facility’s continuous performance criterion concerning new external payment arrears. The IMF ultimately accepted the breach as the consequence of criminal fraud rather than fiscal distress or unwillingness to honour the debt.

But the most important question remains unresolved: how could a sovereign payment system handling millions of dollars remain so dependent on vulnerable email infrastructure?

The reforms now being introduced are substantial. The PDMO has prohibited ordinary email for sovereign debt-payment authorization and introduced a centralised Debt Management Information System. Front, Middle and Back Office functions are being separated, Treasury Secretary approval is required 10 days in advance, lender invoices are to be digitally cross-checked against loan contracts, and foreign bank details must undergo independent diplomatic verification.

Mandatory multi-factor authentication and enhanced threat detection are also being implemented. These measures may close the doors that criminals exploited.

But the larger accountability test is whether Sri Lanka can determine who failed to act when those doors were already known to be unlocked.

Latest Posts

spot_imgspot_img