Tech

Sri Lanka confirms $625,000 payment failure to U.S. Postal Service amid wider cyber theft probes

The disclosure follows a separate $2.5 million loss from the finance ministry, raising questions about the scope of the fraud as Australian officials note irregularities in their own payments.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · original
Sri Lanka discloses another missing payment, days after hackers stole $2.5M from its finance ministry
Treasury Secretary Harshana Suriyapperuma states funds were diverted to other accounts in a suspected business email compromise attack.

The Sri Lankan government has officially confirmed that a payment of approximately $625,000 intended for the U.S. Postal Service has gone missing. This revelation comes after U.S. officials reported that the transfer failed to arrive, prompting local authorities to investigate the discrepancy. The incident emerged days after hackers successfully stole $2.5 million from the country's finance ministry, casting a shadow over the nation's financial security apparatus as it continues to recover from the severe economic crisis that led to its 2022 debt default.

Treasury Secretary Harshana Suriyapperuma addressed the issue during a press conference, stating that the funds were diverted to other bank accounts rather than reaching the intended recipient. Authorities believe the recent loss resulted from a business email compromise attack, a method where cybercriminals breach email inboxes or accounting systems to manipulate bank details and routing numbers during invoice payments. This specific fraud attempt was detected after hackers allegedly tried to divert a separate payment intended for India, highlighting the sophistication of the threat actors targeting Sri Lankan institutions.

The scope of these financial irregularities appears to extend beyond the United States and India. Australian officials are reportedly aware of irregularities in payments owed to Australia, suggesting that the thefts may be broader than initially reported. This development adds significant pressure on the Sri Lankan government, which is still grappling with the aftermath of months of protests and the ouster of then-President Gotabaya Rajapaksa following the nation's fiscal collapse.

Business email compromise scams remain a primary source of profit for cybercriminals globally, with recent FBI data indicating that such attacks resulted in billions of dollars in losses last year alone. The Sri Lankan finance ministry was previously targeted in the separate $2.5 million theft via a similar diversion method, reinforcing concerns about systemic vulnerabilities in the country's payment processing and email security infrastructure.

In response to the mounting evidence of fraud, Member of Parliament Nalinda Jayatissa has initiated an investigation to determine whether the $625,000 loss and the previous $2.5 million theft are linked. While it remains unclear if the two incidents share a common origin, the successive security lapses underscore the urgent need for enhanced cybersecurity measures within the public sector. As the investigation unfolds, the focus remains on securing the remaining assets and preventing further exploitation of the nation's fragile economic recovery.

Continue reading

More from Tech

Read next: France Enacts Strict Ban on Unsolicited Telemarketing Calls
Read next: OpenAI expands Daybreak cybersecurity programme with new model tiers
Read next: AI models map 766 genes in schizophrenia genetic architecture