Skip to content
Business email compromiseUnknown

Hackers divert $2.5 million of Sri Lanka's debt repayment to Australia

Sri Lanka's Ministry of Finance confirmed that attackers who infiltrated the External Resources Department's systems and intercepted email about a government-to-government debt repayment altered payment details and diverted about $2.5 million owed to Australia.

Victim
Sri Lanka Ministry of Finance
Loss
$2.5M

On 23 April 2026, Sri Lanka's Ministry of Finance confirmed that cybercriminals had diverted about $2.5 million that was meant for a government-to-government debt repayment to Australia. Finance Ministry Secretary Harshana Suriyapperuma said attackers had infiltrated computer systems of the ministry's External Resources Department and intercepted email communications about the payment. By altering the payment details, they sent the money to other bank accounts.

According to the ministry, the breach took place in late 2025 and the intrusion was discovered in January 2026. Reporting indicated the theft came to light after Australia flagged that it had not received the expected payment. Australia's High Commissioner, Matthew Duckworth, said Australian officials were aware of the payment irregularities and were helping with the investigation.

Investigation and response

The ministry notified the Sri Lanka Computer Emergency Readiness Team (SL-CERT), the Computer Crimes Investigation Division, the Criminal Investigation Department, the Central Bank's Financial Intelligence Unit and the Australian High Commission. An internal committee led by two Deputy Secretaries to the Treasury was appointed, disciplinary action was taken against certain officials, and senior officers of the Public Debt Management Office were suspended. The ministry said it had kept the case confidential until then so as not to obstruct investigators or alert the criminals.

Why it matters

The case is described as the largest cyber theft recorded from a Sri Lankan state institution. It hit a country still restructuring its debt after its 2022 default, and it shows that business email compromise, more often associated with companies and suppliers, can also target sovereign payments between governments when payment instructions are confirmed by email alone.

Timeline

  1. Finance Ministry Secretary Harshana Suriyapperuma confirms that about $2.5 million meant for a debt repayment to Australia was diverted to other bank accounts.

Sources

  1. english.newsfirst.lkhttps://english.newsfirst.lk/2026/04/23/sri-lanka-confirms-hackers-diverted-usd-2-5-million-meant-for-australian-debt-repayment
  2. openthemagazine.comhttps://openthemagazine.com/world/sri-lankas-finance-ministry-breached-hackers-steal-25m-from-debt-repayment-fund

Related incidents

Zero-dayContained

NAIC confirms data breach after Oracle PeopleSoft zero-day exploited by ShinyHunters

The National Association of Insurance Commissioners disclosed on 23 June 2026 that attackers exploited an Oracle PeopleSoft zero-day to access part of its environment, and by 25 June the extortion group ShinyHunters had published the stolen data online, claiming more than 3.1 terabytes.

Victim
National Association of Insurance Commissioners (NAIC)