Connect with us

News

No cyber hack: Fintech expert exposes shocking legacy flaws that led to $2.5 million theft

Published

on

The alleged diversion of Sri Lanka’s $2.5 million debt repayment is unlikely to be a simple “hack,” but rather a case of a compromised payment process, where weak verification layers, email-based instructions, and insufficient system segregation created an opening for fraud, a fintech expert told The Island Financial Review.

He pointed out that in cross-border public payments, especially sovereign debt servicing, transactions typically moved through multiple controlled layers: payment instruction generation, authentication, bank routing (often via SWIFT), and final settlement.

Elaborating on the matter, he noted, “For funds to ‘miss’ the intended creditor and reach a third party, one of two things must happen: either the payment instructions themselves are altered before execution, or the beneficiary details are fraudulently substituted during the approval chain. The reports I see suggest a Business Email Compromise (BEC) scenario rather than a deep, system-level cyber intrusion.”

“In such attacks, hackers gain access to or spoof official email accounts and send seemingly legitimate payment instructions with altered bank details. If Treasury officials relied on email as a trusted channel without independent verification, such as callback protocols or cryptographic authentication, the system could have been easily deceived. This is not a failure of encryption in transit; emails may still be encrypted. The failure probably lay in identity assurance and process integrity.”

When asked whether end-to-end encryption would have prevented this, he said, “Encryption protects data from interception, but it does not confirm that the sender is genuine or that the instructions are legitimate. What is required here is a zero-trust architecture, meaning every instruction must be verified independently, regardless of the source. Modern Treasury systems, including those at commercial banks, use multi-factor authentication, digital signatures, and secure payment gateways integrated directly with banking systems – removing the reliance on email altogether.”

“Another technical gap appears to be the lack of straight-through processing (STP). In well-designed sovereign payment systems, payment instructions flow directly from Treasury platforms to Central Bank or correspondent bank systems through secure APIs or SWIFT interfaces, with minimal human intervention. If manual steps, such as email confirmations or document attachments, are still embedded in the workflow, they create vulnerabilities.”

“The institutional transition of debt management functions away from the Central Bank may also have introduced operational fragmentation. If there isn’t a unified digital infrastructure and clearly defined control points, accountability gaps emerge.”

“Given that President Anura Kumara Dissanayake also holds the digital infrastructure portfolio, and with advisory leadership from Dr. Hans Wijesuriya, this incident raises questions about execution rather than intent. A country pursuing a digital economy must ensure that its most sensitive financial operations are built on secure, interoperable, and audited platforms.”

“In practical terms, a better-coordinated strategy between the Finance Ministry and digital infrastructure authorities could have enforced mandatory secure channels, real-time transaction monitoring, and anomaly detection systems. Large-value sovereign payments should trigger automated red flags if beneficiary details change or deviate from historical patterns.”

“Ultimately, this episode underscores that digital transformation is not just about adopting technology – it is about redesigning processes, enforcing trust frameworks, and eliminating legacy practices like email-based approvals. Without that, even the most well-intentioned digital agenda remains exposed to very analog fraud,” he concluded.

By Sanath Nanayakkare



News

Geneva takes up Sallay’s case and govt. ignores opportunity to answer accusations

Published

on

Suresh Sallay

The government has chosen not to respond to questions raised by the United Nations Human Rights Council (UNHRC) regarding the detention of retired Maj. Gen. Suresh Sallay in connection with the ongoing investigations into the 2019 Easter Sunday attacks.

The Criminal Investigation Department (CID) arrested the ex-official in late February this year. The Special Rapporteur on the promotion and protection of human rights and fundamental freedoms while countering terrorism, the Working Group on Arbitrary Detention, the Special Rapporteur on the right of everyone to the enjoyment of the highest attainable standard of physical and mental health and the Special Rapporteur on the independence of judges and lawyers have jointly raised the issue on 20 July, 2026.

Drawing attention of President Anura Kumara Dissanayake to what they called alleged arbitrary detention of Sallay, former Director General of the State Intelligence Service (SIS) and former Director of Military Intelligence (DMI), under the Prevention of Terrorism Act (PTA), as well as allegations of torture and other cruel, inhuman or degrading treatment while in custody, resulting in the grave deterioration of his health, and imminent risks of retaliation through further torture and ill-treatment resulting in irreparable harm, should he be released from hospital and returned to custody, the UN sought the government explanation with a 60-day period.

The UN has stated: “This communication, and any response received from your Excellency’s Government, will be made public via the communications reporting website at the 60 days mark. Should your Excellency’s Government respond within 60 days, both the communication and the response, may be published before the 60 days mark. The communications and responses

will also be made available in the subsequent periodic report to be presented to the Human Rights Council.”

In the absence of the government’s response, the UN posted the letter, dated 20 July, 2026, addressed to President Dissanayake. The full letter can be accessed https://spcommreports.ohchr.org/TMResultsBase/DownLoadPublicCommunicationFile?gId=31125

Continue Reading

News

Section of wartime KKS High Security Zone vacated to facilitate economic development in the area

Published

on

The Army, last week, vacated an area, within the wartime high security zone in the Jaffna peninsula. The Defence Ministry said that an extent of 187.56 acres of land, belonging to the Cement Corporation in Kankesanthurai, Jaffna, has been released by the military. The released land, located in Grama Niladhari Division J/233, Kankesanthurai West, within the Valikamam North (Tellippalai) Divisional Secretariat Division, had been utilised by the Sri Lanka Army since the middle of 1997.

The release of the 187.56-acre extent forms part of the initiative to make State land available for the proposed investment zone in Kankesanthurai, thereby facilitating future investment and economic development in the area.

Continue Reading

News

Lawyer lodges complaint against Govt. Printer, Media Ministry Secy.

Published

on

A complaint has been lodged with the Colombo Fraud Investigation Bureau against the Government Printer and the Secretary to the Ministry of Media regarding the online release of falsified documents bearing a forged Speaker’s certificate.

Attorney-at-Law Aruna Laksiri has lodged a complaint with the Colombo Fraud Investigation Bureau requesting legal action against the Government Printer of the Department of Government Printing (No. 118, Dr. Danister de Silva Mawatha, Colombo 08), Prasanna Jayaratne, and the Secretary to the Ministry of Mass Media (Asidisi Medura, 163, Kirulapone Mawatha, Polhengoda, Colombo 05), Dr. Anil Jasinghe.

The complaint alleges the commission of offences by forging and uploading falsified documents online using a forged Speaker’s certification, failure to perform statutory duties, and misappropriation of public property.

The complaint states that a copy of the English translation of the 22nd Amendment to the Constitution was downloaded and printed from the official website of the Government Printing Department (www.documents.gov.lk), which operates under the Ministry of Mass Media. On its outer cover and on page 1, the text “certified on 25th of September, 2026” is inscribed inside brackets.

The complaint pointed out that the Speaker has certified an English translation. Under Articles 23, 79, 83, and 80 of the Constitution, Parliament enacts laws and the Speaker certifies bills strictly in the Sinhala and Tamil languages; under the Constitution, therefore the Speaker cannot apply such certification to an English translation.

Continue Reading

Trending