Treasury Loses $2.5 Million in Business Email Compromise Attack
Article Content
- •Cybercriminals executed a BEC attack, diverting $2.5 million from the Treasury.
- •The attack exploited internal control weaknesses during a transitional period in debt management.
- •The CBSL and Finance Ministry are in conflict over responsibility for the missing funds.
A report from the Treasury revealed that cybercriminals executed a Business Email Compromise (BEC) scheme, diverting $2.5 million in debt payments to an unauthorized account. The attack exploited administrative lapses and compromised internal controls within the Treasury's External Resources Department. The funds were meant for a bilateral loan repayment to Australia but were transferred in multiple transactions between November 18, 2025, and mid-January 2026. The Central Bank of Sri Lanka (CBSL) and the Finance Ministry are currently in a dispute over accountability for the incident. The Criminal Investigation Department is collaborating with Interpol and other organizations for recovery efforts. Emergency measures have been implemented to prevent future phishing incidents, including mandatory telephone callbacks for transaction confirmations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Finance Ministry in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…