ECONOMYNEXT – Sri Lankas Parliament yesterday become the backdrop for an intense debate following the release of the Committee on Public Finance (COPF) report on a $2.5 million cyber fraud involving sovereign debt service payments.
The discussion exposed sharp divisions between government and opposition factions regarding institutional accountability, cybersecurity failures, and administrative oversight during a transition period in public debt management.
Here is an in-depth breakdown of key arguments that unfolded.
Bipartisan Consensus on Fraud and Top-Level Lapses
Opening the discussion on behalf of COPF Chairman Harsha de Silva, Opposition MP Kabir Hashim said both government and opposition members signed off on the COPF report’s conclusions, confirming a major breach in sovereign debt operations.
He noted that transitioning debt management under the Public Debt Management Act created coordination gaps between the Ministry of Finance and the Central Bank. Hashim condemned the suspension of four junior officers — linking the workplace pressure to the tragic suicide of an official — and urged a forensic audit by an independent third party.
Hashim quoted the report regarding executive oversight:
“In the report of the Committee on Public Finance, as agreed upon and signed by both government and opposition MPs, the conclusions clearly state that senior officials at the level of the Treasury Secretary and the Central Bank Governor must bear responsibility for several lapses,” Hashim said.
Government Defends Response
The administration maintained that its reaction to the breach was immediate and appropriate once the fraud was detected.
Minister of Labor and Deputy Minister of Finance and Planning Anil Jayantha claimed the government acted promptly upon detecting suspicious transactions, alerting law enforcement, Sri Lanka CERT, and international investigative agencies.
Jayantha said the $2.5 million diversion occurred because fraudulent email instructions altered bank account details during a transition of functions to the Public Debt Management Office (PDMO). He claimed that long-standing internal control weaknesses inherited from past administrations enabled the exploit.
Jayantha blamed the opposition for politicizing a cyber-attack:
“What is clearly visible here is that they are trying to stack this against the large number of allegations under various previous governments before ours… and attempting to frame it as the biggest fraud,” Jayantha said.
Opposition Slams Broader Governance Failures
Framing the incident strictly as a technical hack misses the larger structural reality.
Leader of the Opposition Sajith Premadasa argued that categorizing the incident solely as a cybercrime masks deeper structural, governance, and operational shortcomings.
Premadasa pointed out that no Standard Operating Procedures (SOPs) or Memorandum of Understanding (MOU) were in place between the Central Bank and the Treasury during the interim transition period, creating severe institutional friction.
He noted that security audits revealed weak passwords and a lack of multi-factor authentication on Treasury email servers.
Premadasa challenged the government’s framing of the security breach:
“Is this really just a cybercrime? It is a governance issue, a procedural issue, and an operational issue. It is stated very clearly that there was weak governance throughout the process of foreign debt repayment in this country.”
Operational Flaws and International Reputation at Risk
The mechanics of how the fraud unfolded reveal a sequence of missed flags and procedural gaps.
Opposition MP Ravi Karunanayake stressed that the state’s external standing faces severe damage due to a breakdown in basic due diligence and verification protocols during a pivotal structural shift.
Detailing the timeline, Karunanayake pointed out that following the enactment of the Public Debt Management Act on June 18, 2024, and a subsequent Coordination Council decision on September 23, 2025, the Director General of the Public Debt Management Office (PDMO) under the Finance Ministry was slated to assume responsibility for sovereign debt payments by January 1, 2026.
As transitional training commenced in mid-October 2025 alongside Central Bank staff, cybercriminals targeted the External Resources Department (ERD) on November 13 with six manipulated invoices, which were passed to PDMO trainees the following day.
By November 15, fraudulent communications impersonating “Ian Gates” — purportedly representing Australian debt — directed funds to an Abu Dhabi account before hackers revised instructions on November 25 to redirect payments meant for Export Finance Australia to a Minneapolis bank.
Despite the US Federal Reserve raising flags on suspicious activity as early as November 24, and both the Fed and JP Morgan issuing fraud alerts, the Finance Ministry submitted a formal payment requisition two days later.
The Central Bank executed the transfer without verifying why Australian loan repayments were destined for a bank account in Minneapolis.
Karunanayake highlighted the lack of verification:
“Fake facts were sent, they were accepted, and payments were processed. Because of this, people in Australia are laughing, saying, ‘Look at these fools in Sri Lanka falling for this,” Karunanayake said.
He criticized both the Central Bank and the Ministry of Finance for passing responsibility back and forth, arguing that a lack of basic verification protocols allowed fake invoices to pass through the payment pipeline.
Systemic Vulnerabilities and Future Safeguards
Deputy Minister of Industry and Entrepreneurship Development Chathuranga Abeysinghe said public sector institutions have suffered from decades of delayed digital upgrades and missing internal verification controls.
He noted that after discovering the breach, the Finance Ministry established strict new protocols, including official channels via embassies, TOD transaction verification units, and 10-day advance Treasury Secretary sign-offs.
Abeysinghe said interim suspensions were necessary to clear space for an independent probe.
“Due to an internal control failure that persisted over a long period, we lost $2.5 million, and tragically, an officer lost their life.”
Expired Security Contracts and Legal Actions
Technical disclosures regarding server maintenance added a further layer of controversy to the debate.
Opposition MP Ajith P Perera pointed out that the Microsoft Exchange Server used by the Ministry lost its security certification in October 2025, leaving communication channels completely exposed right before the fraudulent transfers took place.
He called for formal criminal proceedings under Parliamentary Standing Order 119(4), urging that the matter be referred immediately to the Criminal Investigation Department (CID) and the Bribery Commission for a full investigation into administrative negligence.
Perera pointed directly to the lapsed security infrastructure:
“The Microsoft Exchange Server installed in 2016 had its valid period expire on October 14, 2025… The security certification for this server was terminated by Microsoft on 2025/10/14.”
Public Security Minister Ananda Wijepala insisted that American financial intelligence investigators had traced the movement of the stolen 2.5 million dollars and shared the digital trail with Sri Lankan authorities.
However, since the stolen cash was routed into global networks of secondary “mule accounts,” across several countries including the US, Australia, the UAE, Switzerland, and Zambia, physically retrieving the total sum is inherently complex and difficult.
During parliamentary briefings, COPF acknowledged that if international recovery efforts fail, Sri Lankan taxpayers will ultimately have to bear the burden.
The Ministry of Finance will have to deploy state funds to repay the 2.5 million dollar debt settlement owed to Australia. (Colombo/Aug6/2026)