Sri Lanka's Parliament held a heated debate on a cyber fraud that diverted $2.5 million in sovereign debt payments, with government and opposition members disagreeing over whether the incident was primarily a technical security breach or a systemic governance failure.
Parliament became a forum for intense disagreement this week following the release of a Committee on Public Finance (COPF) report examining a $2.5 million fraud targeting sovereign debt service payments. While both government and opposition members signed the COPF report confirming a major breach in debt operations, they sharply diverged on underlying causes and responsibility. Opposition MP Kabir Hashim stated that the report concluded senior officials at the Treasury Secretary and Central Bank Governor level bore responsibility for multiple lapses, and called for an independent forensic audit. He also condemned the suspension of four junior officers, linking workplace pressure to the suicide of one official.
The government maintained that its response was immediate and appropriate. Deputy Minister of Finance Anil Jayantha argued that the $2.5 million diversion occurred when fraudulent email instructions altered bank account details during a transition of debt management functions to a new Public Debt Management Office. Jayantha attributed the vulnerability to internal control weaknesses inherited from previous administrations and accused the opposition of politicizing the incident. However, Leader of the Opposition Sajith Premadasa rejected this framing, arguing that describing the incident solely as cybercrime masked deeper structural and governance failures, including the absence of proper procedures and coordination between institutions during the transition period.
Opposition MP Ravi Karunanayake provided a detailed timeline showing that after the Public Debt Management Act took effect in June 2024, cybercriminals targeted the External Resources Department with fraudulent invoices in November 2025. Despite the US Federal Reserve raising concerns about suspicious activity on November 24, the Finance Ministry submitted a payment requisition two days later, and the Central Bank executed the transfer without verifying why Australian loan repayments were directed to a Minneapolis bank account. Opposition MP Ajith P Perera highlighted that the Ministry's Microsoft Exchange Server had lost its security certification in October 2025, leaving communication channels exposed at the critical moment.
Government officials acknowledged systemic vulnerabilities and announced new safeguards including official embassy channels and advance Treasury Secretary verification. However, Public Security Minister Ananda Wijepala noted that recovering the stolen funds proves difficult because the money was routed through secondary accounts across multiple countries including the US, Australia, the UAE, Switzerland, and Zambia. The COPF acknowledged that if international recovery efforts fail, Sri Lankan taxpayers will bear the burden of repaying the $2.5 million owed to Australia.












