Skip to main content
Security

Sri Lanka reports second missing payment amid ongoing treasury cyber attack investigation

Sri Lanka reports second missing payment amid ongoing treasury cyber attack investigation Image: Primary
The Sri Lankan government has disclosed another missing international payment, just days after revealing that hackers had stolen $2.5 million from its finance ministry. Sri Lankan officials said Tuesday that a payment of approximately $625,000 to the U.S. Postal Service has been unaccounted for over several weeks. U.S. authorities reported that the funds failed to arrive. The incident was detected after hackers attempted to divert a separate payment intended for India. Australian officials are reportedly also aware of irregularities in payments owed to their country. These incidents appear to be business email compromise attacks, in which hackers infiltrate email inboxes or accounting systems to manipulate routing information and redirect payments. Treasury Secretary Harshana Suriyapperuma said last week that the hackers diverted a payment from Sri Lanka's postal authority "to other bank accounts, instead of the intended recipient." The FBI has reported that email compromise attacks continue to be one of the most profitable cybercriminal operations, resulting in billions of dollars in losses annually. The successive disclosures have added pressure on the Sri Lankan government, which continues to recover from a 2022 debt default and economic crisis that led to months of protests and the ouster of then-president Gotabaya Rajapaksa. It is currently unclear if the two recent thefts are connected. Member of Parliament Nalinda Jayatissa said the government is investigating whether the incidents are linked.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechCrunch and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products Security
Products Security

Figma launches Japan data residency for enterprise file hosting

Figma introduced data residency in Japan, letting enterprise customers store Figma Design, FigJam, Figma Slides, and Figma Make file data in the country. The company said the option responds to customer demand for domestic storag...

Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...

Security Infrastructure
Security Infrastructure

GitLab patches maximum-severity file-read flaw as probes hit exposed servers

GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...