Thursday, April 23, 2026

Sri Lanka: USD 2.5 million Treasury payment diverted to hackers? – Opposition demands urgent probe

Sri Lanka faces a potential cybersecurity crisis as opposition lawmakers demand an urgent investigation into the alleged diversion of $2.5 million in Treasury payments to hackers. The incident has raised serious questions about the country's financial security infrastructure and debt management capabilities during a critical economic recovery period.

Opposition Raises Alarm Over Missing Funds

Opposition Member of Parliament Harsha De Silva has brought the alleged cybersecurity breach to public attention, questioning the whereabouts of $2.5 million belonging to the Sri Lankan people. "What happened to $2.5 million of the Sri Lankan people's money? Disappeared!" De Silva stated, highlighting the gravity of the situation.

The MP emphasized that this incident represents more than simple negligence, describing it as a systemic failure that opposition members had previously warned against. The controversy centers around recent changes in Sri Lanka's debt management operations, which were transferred from the Central Bank of Sri Lanka (CBSL) to the Treasury's Public Debt Management Office (PDMO).

Warnings Ignored: COPF's Previous Concerns

According to De Silva, the Committee on Public Finance (COPF) had repeatedly urged the Treasury to hire competent and experienced staff when debt operations were relocated to the PDMO. The opposition claims these warnings went unheeded, potentially contributing to the current security vulnerability.

The transfer of debt management responsibilities from the CBSL to the Treasury's PDMO was part of broader financial restructuring efforts in Sri Lanka. However, the alleged hacking incident suggests that adequate cybersecurity measures may not have been implemented during this transition period.

Cybersecurity Vulnerabilities in Government Systems

This alleged breach highlights significant cybersecurity vulnerabilities within Sri Lanka's government financial systems. Managing sovereign debt operations requires robust security protocols, given the sensitive nature of international financial transactions and the substantial amounts involved.

The incident occurs at a particularly sensitive time for Sri Lanka, as the country continues to navigate through its worst economic crisis in decades. The nation has been working to restructure its debt and restore international confidence in its financial management capabilities.

Impact on Economic Recovery Efforts

The timing of this alleged cybersecurity breach could not be worse for Sri Lanka's economic recovery efforts. The country has been working diligently to rebuild trust with international creditors and financial institutions following its economic collapse in 2022.

Any perception of weakness in financial security systems could potentially undermine ongoing negotiations with creditors and impact future borrowing costs. International lenders and investors closely monitor the financial management capabilities of borrowing nations, particularly those undergoing debt restructuring processes.

Calls for Immediate Investigation

Opposition members are demanding a comprehensive investigation into the alleged incident, seeking answers about how the security breach occurred and what measures are being taken to prevent similar incidents in the future.

The investigation demands include examining the cybersecurity protocols in place at the PDMO, reviewing the staff qualifications and training programs, and assessing the overall security infrastructure of government financial systems.

Implications for Debt Management Operations

The alleged hacking incident raises questions about the effectiveness of transferring debt management operations from the Central Bank to the Treasury. While such transfers are often part of modernizing financial administration, they require careful implementation with adequate security measures.

Sovereign debt management involves complex international transactions that require sophisticated security protocols. The alleged breach suggests potential gaps in the transition process that may have created vulnerabilities exploited by cybercriminals.

Government Response and Transparency

As of now, there has been limited official government response to the opposition's allegations. The lack of immediate transparency regarding the incident has further fueled concerns about the administration's handling of financial security matters.

Public accountability demands that the government provide clear explanations about any security breaches involving public funds, particularly given Sri Lanka's current economic circumstances and the need to maintain public trust.

Moving Forward: Strengthening Financial Security

Regardless of the investigation's outcome, this incident underscores the urgent need for Sri Lanka to strengthen its financial cybersecurity infrastructure. The country must invest in robust security systems, qualified personnel, and comprehensive training programs to protect public funds from cyber threats.

The alleged $2.5 million diversion serves as a wake-up call for enhanced cybersecurity measures across all government financial operations. As digital threats continue to evolve, Sri Lanka must ensure its financial systems can withstand sophisticated cyberattacks while maintaining the integrity of public fund management.

The opposition's call for an urgent probe represents a critical step toward accountability and transparency in government financial operations during these challenging economic times.