Sri Lanka's Parliament held a heated debate following a Committee on Public Finance report on a $2.5 million cyber fraud affecting sovereign debt payments. The discussion revealed sharp divisions between government and opposition over accountability, cybersecurity failures, and institutional oversight during a debt…
Parliament became the venue for an intense political debate on Thursday following the release of a Committee on Public Finance report detailing a $2.5 million cyber fraud involving sovereign debt service payments. The bipartisan committee report confirmed a major breach in sovereign debt operations, with both government and opposition MPs signing off on conclusions that senior officials at the Treasury and Central Bank levels bear responsibility for several lapses. The fraud occurred during a transition period when debt management functions were shifting to the newly established Public Debt Management Office under the Public Debt Management Act.
The incident unfolded through a series of procedural failures beginning in mid-October 2025 when transitional training commenced between the Finance Ministry and Central Bank. Cybercriminals targeted the External Resources Department in November with fraudulent communications impersonating an Australian debt representative, directing funds to accounts in Abu Dhabi and later Minneapolis. Despite alerts from the US Federal Reserve and JP Morgan flagging suspicious activity, the Central Bank executed transfers without verifying why Australian loan repayments were destined for foreign bank accounts. Opposition members highlighted that no Standard Operating Procedures or Memoranda of Understanding existed between institutions during the transition, creating coordination gaps that enabled the exploit.
The government defended its response as immediate and appropriate, claiming it acted promptly upon detecting suspicious transactions and alerting law enforcement and international agencies. Deputy ministers attributed the breach to long-standing internal control weaknesses and decades of delayed digital upgrades, noting that the Microsoft Exchange Server protecting Treasury communications had expired security certification in October 2025. The administration also suspended four junior officers and established new protocols including embassy verification channels and advance Treasury Secretary approvals. However, opposition leaders argued the incident represents a broader governance failure rather than merely a technical cybercrime, pointing to weak passwords, absent multi-factor authentication, and inadequate verification procedures as systemic failures.
The fate of the stolen funds remains uncertain. Public Security Minister Ananda Wijepala stated that American investigators traced the money through global networks of secondary accounts across multiple countries, including the US, Australia, the UAE, Switzerland, and Zambia. The committee acknowledged that if international recovery efforts fail, Sri Lankan taxpayers will bear the financial burden as the state must repay the debt settlement owed to Australia. Opposition MPs have called for criminal proceedings under parliamentary standing orders, urging referral to the Criminal Investigation Department and Bribery Commission for investigation into administrative negligence.












