Sri Lanka's Parliament debated a major cyber fraud involving $2.5 million in sovereign debt payments, with government and opposition lawmakers disagreeing sharply over whether the incident was purely a cybersecurity breach or a symptom of deeper governance failures.

Parliament conducted a heated debate on a Committee on Public Finance report examining a $2.5 million fraud in sovereign debt service payments, revealing significant disagreements between government and opposition over institutional accountability and security oversight. While both sides acknowledged the breach occurred during a transition of debt management functions to the newly established Public Debt Management Office, they diverged sharply on root causes and responsibility.

Opposition lawmakers characterized the incident as fundamentally a governance failure rather than a simple cyber attack. Leader of the Opposition Sajith Premadasa argued that the fraud exposed deeper structural problems, including absent coordination protocols between the Central Bank and Treasury during the transitional period, weak passwords on Treasury email servers, and a lack of multi-factor authentication. Opposition MP Ravi Karunanayake detailed how fraudsters impersonating Australian debt officials redirected payments to accounts in Abu Dhabi and Minneapolis between November and December 2025, despite early fraud alerts from the US Federal Reserve and JP Morgan. He criticized both institutions for failing to verify suspicious payment instructions before processing transfers.

The government maintained it responded appropriately once fraudulent activity was detected, characterizing the breach as an exploit of legacy security weaknesses inherited from previous administrations. Deputy Minister of Finance Anil Jayantha stated that the administration immediately alerted law enforcement and international agencies upon discovery. The government also highlighted new security protocols subsequently implemented, including official embassy channels and advance Treasury Secretary approval requirements. However, opposition MP Ajith P Perera pointed out that the Microsoft Exchange Server used by the Finance Ministry had its security certification expire on October 14, 2025—just weeks before the fraudulent transfers occurred.

Both sides acknowledged that four junior officers were suspended following the incident, with concerns raised about workplace pressure linked to an official's tragic suicide. The debate also revealed that international recovery efforts remain uncertain, with stolen funds traced through multiple countries. Officials acknowledged that if recovery fails, Sri Lankan taxpayers may ultimately bear the $2.5 million loss owed to Australia.