Speed Read
- Two major payment diversion incidents, the Treasury and Postal Department, point to systemic failures rather than isolated cyberattacks.
- Sri Lanka’s Committee on Public Finance found that recommendations from Sri Lanka’s Computer Emergency Readiness (CERT) team, security audits, and Cabinet-approved cybersecurity policies went largely unimplemented.
- SLCERT’s government cybersecurity policy, approved by the Cabinet, had already warned of the very weaknesses exposed by the Treasury fraud, including weak information security, obsolete technologies, and a shortage of skilled cybersecurity personnel.
- The COPF found that SLCERT lacked the legal authority to enforce its cybersecurity recommendations, leaving a critical gap between technical advice and implementation across government institutions.
COLOMBO—On July 22, when the Criminal Investigation Department (CID) informed the Colombo Magistrate’s Court that more than $626,000 (Sri Lankan rupees 210,773,699) belonging to the Department of Posts had allegedly been diverted into nine bank accounts, it appeared to be another cyber-enabled financial crime targeting a government institution.
According to investigators, the payment, intended for the United States Postal Service, was allegedly redirected after fraudsters exploited the department’s email system, using an email address outside the official communication channel established by the Universal Postal Union.
The investigation is ongoing.
Yet the allegations bear striking similarities to another case that has already exposed deep weaknesses in Sri Lanka’s public sector. The Treasury cyber fraud, in which $2.5 mn (rupees 8,375,000,000) earmarked for sovereign debt repayments to Export Finance Australia was diverted after government officials unknowingly relied on fraudulent email instructions between November 2025 and January 2026
Different institutions.
Different victims.
The same weaknesses.
Viewed together, the two cases suggest something far more troubling than isolated cyber incidents. They point to a pattern of weak digital governance across Sri Lanka’s public sector where ignored cybersecurity warnings, outdated technology, poor internal controls, and weak digital hygiene continue to leave critical institutions vulnerable.
The Parliamentary Committee on Public Finance (COPF), which investigated the Treasury fraud from April 30, concluded in its report submitted on July 7that the theft was not simply the work of sophisticated cybercriminals. It was enabled by years of institutional failures, including outdated IT infrastructure, inadequate cybersecurity awareness, weak internal controls, and the government’s failure to implement recommendations repeatedly made by the Sri Lanka Computer Emergency Readiness Team (SLCERT).
While investigators are yet to determine how the alleged fraud involving the Department of Posts occurred, the case raises an uncomfortable question of lessons from the Treasury fraud not being acted upon.

Misplaced digital hygiene
Cybersecurity discussions often focus on hackers, ransomware, or sophisticated malware. Experts say that the greater threat usually lies much closer to home.
Digital hygiene refers to the routine practices organizations follow to protect their information systems—from using strong passwords and multifactor authentication to updating software, independently verifying financial transactions, and training employees to recognize phishing attempts.
Most of these measures are neither expensive nor technically complex.
Yet, COPF’s investigation suggests that some of the government’s most sensitive institutions consistently failed to perform these basic tasks.
Cybersecurity expert and digital policy leader Asela Waidyalankara told CIR the Treasury fraud exposed three interconnected weaknesses that continue to affect much of Sri Lanka’s public sector –people, processes, and technology.
“The incident was not about one mistake,” he noted. “It demonstrated failures in people, failures in processes and failures in technology governance.”
His assessment mirrors COPF’s findings, which concluded that the fraud succeeded not because cybercriminals possessed extraordinary technical capabilities but because multiple layers of institutional safeguards failed simultaneously.

Warnings already existed
Perhaps the most disturbing aspect of the Treasury fraud is that few of the vulnerabilities were new.
A joint audit conducted by KPMG and SLCERT in December 2024 had already identified serious weaknesses within the Ministry of Finance’s IT environment. The assessment found the absence of multifactor authentication, weak password practices, and poorly defined cybersecurity roles and responsibilities that created significant accountability gaps.
Instead of being promptly addressed, many of those shortcomings remained unresolved well into 2026.
In written submissions to COPF on June 9, SLCERT highlighted that follow-up reviews conducted jointly with the National Cyber Security Operations Centre (NCSOC) in January and April 2026 found many of the same vulnerabilities still existed.
One of the most serious concerns involved the External Resources Department’s (ERD) Microsoft Exchange Server 2016.
Microsoft’s extended security support for the platform ended in October 2025, only weeks before the fraudulent transactions occurred. Yet the ministry continued relying on the unsupported email infrastructure without replacing it, according to COPF report.
SLCERT also cautioned that operating unsupported systems significantly increased the government’s exposure to cyberattacks, while COPF concluded that procurement delays and poor technology planning left critical government systems vulnerable long after the risks had been identified.
The timeline is striking.
Auditors identified weaknesses.
Cybersecurity specialists recommended corrective action.
Follow-up reviews found little progress.
Then millions of dollars disappeared.
The Treasury fraud illustrated what can happen when cybersecurity recommendations become reports sitting on shelves instead of driving institutional reform.

Human error opened the door
According to COPF, cybercriminals manipulated government officials using carefully crafted emails sent from domains that closely resembled legitimate government and lender addresses.
Simple verification procedures that should accompany multimillion-dollar international financial transactions have been overlooked.
Officials continued communicating with fraudulent email addresses even after receiving warnings from the Central Bank about suspicious payment instructions.
Instead of independently verifying revised bank account details through trusted communication channels, they sought clarification from the same fraudulent email accounts that initiated the deception.
For Waidyalankara, those failures reflect a broader cultural problem across government.
Unlike many private-sector organizations, cybersecurity awareness rarely forms part of employee performance or institutional accountability.
“Cybersecurity must become part of everyday work, not remain solely the responsibility of IT departments. Training should be continuous, supported by simulated phishing exercises, regular awareness campaigns, and ongoing assessments, because human error remains the most common entry point for attackers.”
Government, he said, has yet to fully embrace that reality.
“The solutions already exist,” Waidyalankara noted. “The challenge isn’t buying technology. It’s governing it properly.”
Governance failed before technology did
The Treasury investigation exposed a striking paradox.
Sri Lanka did not lack cybersecurity policies.
The SLCERT had already developed an Information and Cyber Security Policy for Government Organizations, aligned with the national cyber security strategy and international information security standards. The Cabinet had approved its implementation across all public authorities covered under the Right to Information Act.
The policy itself acknowledged many of the weaknesses that later contributed to the Treasury fraud.
It warned that government institutions increasingly relied on digital systems while paying insufficient attention to information security, continued using obsolete technologies, and struggled with shortages of skilled cybersecurity personnel.
In other words, government had already diagnosed its own vulnerabilities.
SLCERT’s submissions to COPF reveal a familiar pattern: outdated infrastructure remained in service, multifactor authentication was still absent, weak password practices persisted, and vulnerabilities identified more than a year earlier had yet to be addressed.
Perhaps most significantly, COPF observed that SLCERT lacked the legal authority to compel government institutions to implement its recommendations.
That gap between technical advice and institutional action became one of the parliamentary investigation’s most important findings.

A governance problem
For cybersecurity professionals, the Treasury fraud reinforced one of the industry’s oldest lessons: technology alone cannot protect an organization if its people remain vulnerable.
Nirosh Ananda, chief security information officer of SLCERT told CIR the incident underscored the need for stronger cybersecurity awareness across the public sector.
Following the Treasury fraud, SLCERT urged government institutions to strengthen cybersecurity awareness, improve basic cyber hygiene, and foster a stronger culture of incident reporting.
“Building awareness is one of the most important measures because these incidents often begin with human error,” Ananda said. “Officials need to know how to identify suspicious communications, particularly emails, and follow good cyber hygiene practices.”
He said SLCERT has continued conducting awareness programs across the public sector while encouraging institutions to report suspicious cyber incidents as early as possible rather than waiting until significant damage has occurred.
His observations echoed COPF’s finding that the Treasury fraud resulted more from human and procedural failures than sophisticated hacking techniques.
The Treasury fraud has understandably renewed calls for stronger cybersecurity technologies across government. But experts say that purchasing new software alone will accomplish little unless institutions fundamentally change how they govern technology.
Waidyalankara claimed one of Sri Lanka’s greatest weaknesses is treating cybersecurity as an IT procurement issue rather than a governance responsibility.
Government agencies often invest heavily in digital platforms before gradually neglecting software updates, infrastructure maintenance, staff training, and long-term oversight.
“In a bank, if a critical server is approaching the end of its supported life, replacement planning begins well in advance,” Waidyalankara said. “That level of governance was clearly missing.”
He said responsibility cannot rest solely with institutions like GovTech or the Ministry of Digital Economy.
> “Every ministry that procures technology must also build the capacity to maintain it, manage cybersecurity risks, and seek technical support where expertise is lacking.”
Waidyalankara noted that Sri Lanka has experienced significant cyber incidents before, including the ransomware attack that disrupted government email systems two years ago. Those incidents attracted far less public attention because they did not involve direct financial losses.
“If you are building a road, you do not just lay the asphalt,” he said. “You install the streetlights, the lane markings and the safety features that make it usable. Cybersecurity and data protection are those fundamentals for a digital state.”

Costly governance failures
The Treasury fraud demonstrated that governance failures can be just as costly as technological ones.
As investigators continued examining the alleged diversion of funds from the Postal Department, the government moved to reinforce existing cybersecurity requirements.
On June 22, 2026, Waruna Sri Danapala, secretary to the Ministry of Digital Infrastructure, issued a circular, reminding government institutions that implementing the Information and Cyber Security Policy for Government Organizations is mandatory.
“Cyber-attacks and online financial scams threaten sensitive data, disrupt public services, and cause economic losses, making strong cyber security measures essential for protecting national digital infrastructure,” it stated.
It further reminded heads of government institutions that implementing the policy is their responsibility.
“Heads of organizations are hereby reminded that the implementation of the Policy in their respective organizations is mandatory. As directed by the Cabinet of ministers, it is a responsibility of the heads of the organizations to allocate necessary budgets for cyber security activities through the annual budget.”
The circular reinforces many of the same recommendations that SLCERT and cybersecurity professionals have been making for years.
Whether it translates into meaningful institutional change remains to be seen.
Banner Image: Recent cybersecurity incidents and rising online financial fraud have highlighted the urgent need to strengthen the security of government digital systems. Image courtesy of Amar Preciado via pexels.
This story was written and edited by Gagani Weerakoon. She leads the editorial at the Center for Investigative Reporting (CIR).
This story was produced with support from Report for the World, a global media service strengthening local independent journalism


