ThreatCluster

Treasury Loses $2.5 Million in Business Email Compromise Attack

3h ago Sundaytimes.Lk 75% similarity 72
Share:

Article Content

Browse articles
ThreatCluster

A report from the Treasury revealed that cybercriminals executed a Business Email Compromise (BEC) scheme, diverting $2.5 million in debt payments to an unauthorized account. The attack exploited administrative lapses and compromised internal controls within the Treasury's External Resources Department. The funds were meant for a bilateral loan repayment to Australia but were transferred in multiple transactions between November 18, 2025, and mid-January 2026. The Central Bank of Sri Lanka (CBSL) and the Finance Ministry are currently in a dispute over accountability for the incident. The Criminal Investigation Department is collaborating with Interpol and other organizations for recovery efforts. Emergency measures have been implemented to prevent future phishing incidents, including mandatory telephone callbacks for transaction confirmations.

Key Points: • Cybercriminals executed a BEC attack, diverting $2.5 million from the Treasury. • The attack exploited internal control weaknesses during a transitional period in debt management. • The CBSL and Finance Ministry are in conflict over responsibility for the missing funds.

ThreatCluster AI

Timeline

2025-11-13
Australia notifies Treasury of overdue payment
The Treasury received a letter from Australia regarding a long overdue debt payment, raising suspicions about the request.
Sundaytimes.Lk
2025-11-18
Fraudulent payment transfers initiated
The Treasury processed five transfers totaling $2.5 million to an unauthorized account, following pressure from the Australian party.
Sundaytimes.Lk
2026-06-13
CBSL to respond to Treasury report
The Central Bank of Sri Lanka is expected to respond to the Finance Ministry's report on the missing funds and the ongoing accountability dispute.
Sundaytimes.Lk
2026-06-14
Treasury report released
A 100-page report detailing the BEC attack and administrative lapses was submitted to Parliament, highlighting the need for improved controls.
Sundaytimes.Lk

Community

Browse all →