It has been revealed that during a loan instalment settlement executed through the General Treasury, USD 2.5 million belonging to the Central Bank of Sri Lanka was diverted to an unauthorised third party. This payment was an installment corresponding to a total debt exceeding USD 217,514,119.12 (over USD 217.51 million) acquired across six instances between 2010 and 2016 for five major development projects implemented under Australian financial facilities and relations.
This revelation comes through information provided by the Department of External Resources (ERD) in response to a request filed under the Right to Information (RTI) Act. The letter issued by the ERD under the RTI Act confirmed the loan details pertaining to several major development projects carried out under Australian financial assistance.
A detailed analysis of the data discloses that the total loan amount obtained across multiple sectors for six projects stands at USD 217,514,119.12 (over USD 217.51 million). It has further been uncovered that the missing USD 2.5 million was a bilateral loan installment due to Export Finance Australia (EFA), the Australian government’s export credit agency.
According to data disclosed by the Department of External Resources, these loans were obtained for Phase III (Parts 1 and 2) of the Ampara Water Supply Scheme in 2010 and 2015, amounting to USD 105,190,000.00 and USD 7,538,854.00 respectively, with an applicable interest rate of 6-month LIBOR + 1.00%. Furthermore, under Phases I and II of the Dairy Cattle Importation Project, USD 10,524,492.00 was obtained in 2011 and USD 17,635,199.33 in 2014. Additionally, in 2016, USD 62,860,946.61 was borrowed at 6-month LIBOR + 2.00% for the project to import 20,000 dairy cattle, while in 2015, USD 13,764,627.18 was secured to establish clinical waste management systems in hospitals.
Rejected Information
To uncover the true facts surrounding this financial irregularity through legal avenues, a 19-question application was submitted to several state institutions under the Right to Information (RTI) Act. However, the relevant public authorities evaded disclosing the requested information, citing various reasons. The Central Bank of Sri Lanka (CBSL) rejected providing details on payments and warnings under Section 5(1)(h) of the RTI Act, claiming disclosure would “prejudice the prevention or detection of crime or apprehension of offenders,” while directing the remaining queries to the Ministry of Finance on the grounds that the information was not in its possession, custody, or control.
Similarly, the Public Debt Management Office (PDMO) completely refused to provide any information regarding the USD 2.5 million payment, citing Section 5(1)(h)(i) of the RTI Act. The Ministry of Finance, Planning and Economic Development stated that a preliminary internal inquiry had concluded and that the Criminal Investigation Department (CID) had filed a ‘B Report’ before court; hence, it had sought instructions from the Right to Information Commission to withhold the information. Amidst this widespread evasion by other bodies, only the Department of External Resources disclosed basic facts, including the purpose, total sum, year, and applicable interest rates of the loans.
Nevertheless, as revealed in recent investigative media reports, the USD 2.5 million sum intended for Export Finance Australia was diverted to an external account through an organized cybercrime (Business Email Compromise). Cybercriminals deceived Treasury officials by spoofing the long-standing official domain exportfinance.gov.au with a fraudulent domain, exportfinance-av.com. It is reported that despite a prior security alert issued on October 28, 2025, by system security firm ‘Enable’ regarding the altered email domain, the concerned officials ignored the warning and proceeded with the transaction.
Why Hide Information from the Citizen?
Serious suspicion arises over the fact that information was concealed for several months following the incident without filing a complaint with the CID or security authorities. Following a complaint lodged on March 24, 2026, the Computer Crimes Investigation Division of the CID submitted facts to the Colombo Fort Magistrate’s Court under the Offences Against Public Property Act, the Penal Code, and the Computer Crimes Act. To date, statements have been recorded from 91 individuals, including officials from the General Treasury’s Department of External Resources, the Public Debt Management Office, and the Central Bank. Furthermore, a technical committee from Sri Lanka Telecom is currently cloning data from the Treasury’s server system to investigate whether unauthorized access occurred within the ‘Enable’ data system. Requests made under RTI for these details were likewise rejected by the aforementioned public authorities.
Particularly at a juncture when Sri Lanka is striving to rebuild after a severe financial crisis, the disappearance of a sum as substantial as USD 2.5 million from the State Treasury cannot be dismissed as a mere technical glitch. Violating standard operating procedures (SOPs), ignoring advance security warnings, and delaying reporting to investigative bodies for months clearly points to severe internal negligence or fraud. The practice of state institutions hiding behind court proceedings to undermine the Right to Information Act must cease immediately, and accountability to Parliament and the public must be established through a special audit report by the National Audit Office. Moreover, it remains a critical question as to why authorities are actively suppressing information regarding the timeline and legal actions taken by officials concerning this incident.

