by Our Correspondent in Colombo
Sri Lankan authorities are grappling with the fallout of a major cyber breach targeting the Ministry of Finance, in which approximately USD 2.5 million in Treasury funds were fraudulently transferred to scammers after a system compromise. In efforts to trace the stolen money, assistance was sought from United States authorities, leading to the identification of funds in bank accounts across two different US states. While one account located in Delaware was found to be empty, another account in a separate state still contained only USD 200, which has been flagged for repatriation to Sri Lanka. Officials have noted that although the recovery is minimal compared to the total loss, the amount is expected to be returned, offering limited consolation as the rupee continues to face pressure against a strengthening US dollar.
The incident has intensified scrutiny over financial cybersecurity safeguards within Sri Lanka’s public financial systems, particularly given the scale of the loss relative to the negligible amount recovered. Authorities have described the case as part of an ongoing investigation into how the Treasury transfer was diverted by cybercriminals, with parallel reports suggesting that additional funds, including a separate USD 625,000 payment linked to US postal authorities, may also have been affected by similar fraudulent activity.
Meanwhile, the US Embassy in Colombo has firmly rejected local media claims that a Federal Bureau of Investigation (FBI) team had been deployed to Sri Lanka to assist with the investigation. The embassy clarified that no such team has arrived, emphasizing that only an FBI Legal Attaché operates from the embassy to coordinate law enforcement cooperation when requested by local authorities. Officials stressed the importance of accuracy in reporting sensitive security matters, as speculation continues to circulate around the scope and international involvement in the cyber fraud case.

