Experts and critics have described the ongoing discussion around recovering the US$2.5 million allegedly stolen from Sri Lanka’s Treasury as a “smokescreen,” raising concerns that the focus on recovery efforts may be overshadowing more serious questions about how the cyber theft occurred in the first place. The statement has added further controversy to an already sensitive financial security incident.
The Sri Lanka Computer Emergency Response Forum had earlier reported that hackers used phishing techniques to impersonate trusted entities and manipulate information systems, enabling the fraudulent transfer of funds. Following the incident, discussions have been held at the Ministry of Finance, with authorities examining the scale of the breach and possible technical responses.
However, some experts argue that public emphasis on recovery is misleading, suggesting it may be shifting attention away from systemic weaknesses that allowed the attack to succeed. They claim that without addressing structural vulnerabilities in state financial cybersecurity systems, recovery discussions alone risk becoming symbolic rather than substantive. The incident has therefore sparked broader debate over accountability, transparency, and the effectiveness of national cyber defense mechanisms.

