← Sri Lanka Ministry Finance

2026 Sri Lanka Ministry of Finance — ~USD 2.5M fraudulent payment diversion (cyber heist; Apr)

2026 Unknown records affected Share on X

Data compromised

Fraudulent fund transfer; not primarily a PII exfiltration event

Technical writeup

In April 2026, the government of Sri Lanka and international press (BBC, Reuters, NDTV, Hindustan Times) reported that cybercriminals manipulated or compromised the Ministry of Finance’s payment workflows—linked in coverage to the External Resources Department / public debt management context—and diverted roughly USD 2.5 million in funds (described in journalism as intended for a sovereign payment such as a debt service transaction to Australia). Authorities suspended senior officials, opened investigations with domestic police and international coordination, and treated the event as a major public-sector financial cybercrime. This is a treasury/payment-integrity incident rather than a mass citizen PII database leak; no unified count of personal records applies.

Root cause

Compromised or abused payment/authorization process in finance ministry systems (per government and press—forensic details evolving)

References