General23 July 2026

Central bank unveils shocking more details contradicting Finance ministry claims in Treasury heist

The Central Bank of Sri Lanka today (23) made public the detailed submissions it had earlier placed before the Committee on Public Finance, on the USD 2.5 million fraud on the country's foreign debt payments. The picture that emerges is a devastating one for the Ministry of Finance.

In its submissions, the Central Bank told the Committee that the root cause of the fraud was, in its own phrase, "totally outside" the institution. The theft, it said, and again these are its words, "was directly precipitated by tampered payment instructions generated from the compromised email system at the Ministry of Finance." The Bank's submissions describe the Ministry's account of events as, in five separate places, "factually incorrect," and further as "misleading," "legally untenable," and, in two instances, "categorically denied."

The Bank was blunt on one particular Ministry claim. Instead of confirming the beneficiary details with the real lender, in its words, "the Ministry of Finance proceeded to seek such information from the fraudulent source."

The Central Bank also took direct aim at a Ministry accusation that its officers had not been properly trained.

The submissions record that officials of the new Public Debt Management Office had been holding their own system login credentials since the 13th of October last year, were independently creating standard settlement instructions in the days that followed, and had, before the Australian payments were even touched, successfully entered, verified, authorised and completed a series of seven transactions of their own accord.

Four settlement instructions were created by them, on their own, before the fraudulent invoices arrived. The system logs, the Bank told the Committee, are unambiguous on the point.

The rest of the documents released today read as a catalogue of failures at the Ministry side.

On the 26th of November, the Central Bank warned the Ministry, in writing, that the beneficiary address on the payment request was, and this is a quotation from the letter, "not the address of Export Finance Australia," and added that this "will be a matter regarding anti-money-laundering." The Ministry's response was to pay USD 997, 799 to a shell company account in the United Arab Emirates, on the 17th of December.

When that payment was recalled by the receiving side, the Ministry paid the same invoice, to the same account, all over again on the 20th of January.

The Acting Director of the External Resources Department emailed the fraudster directly, at the fake domain exportfinanceau.com, and disclosed the exact amount that had just been returned.

The fraudster's next invoice was written for that returned amount, correct to the last cent, credited down to USD 422.37.

The tampered invoices themselves, on their face, named "Mish Global LLC" and "LMH Global LLC, in care of Export Finance and Insurance Corporation." And they were annotated, in the Ministry's own hand, with minutes reading, in one case, "please pay immediately." No one at the Ministry, on the record, appears to have thought any of this suspicious.

All four of the fake settlement instructions used to route the money were entered, updated, and approved entirely by Public Debt Management Office user accounts, in a two-hour window on the 13th of November 2025. The Central Bank's system logs make that clear, and the Committee accepted them.

On the cyber side, the picture is worse still. The External Resources Department was, at the time of the fraud, running its email system on Microsoft Exchange Server 2016, for which the manufacturer's security updates had ceased on the 14th of October 2025. The fraud began in the middle of November. In the Committee's own phrase, "it is therefore far more than a coincidence."

The warnings, the record shows, had already been given. A joint audit by KPMG and the Sri Lanka Computer Emergency Readiness Team, back in December 2024, had found no multifactor authentication in place, weak passwords, and undefined roles across the Ministry's systems. Those same vulnerabilities were flagged again in January and April of this year. The Cabinet had ordered the Ministry to connect its systems to the National Cyber Security Operations Centre, and reminder letters went out to enforce that order in March, October, January, and again in March. As of last month, the Ministry was still, in its own words, "in the process of establishing connectivity."

Elsewhere in the Central Bank's submissions is a fact that borders on the surreal for a sovereign debt office. All twelve officials of the Public Debt Management Office were listed with personal Gmail and Yahoo addresses. The three international ratings agencies, Standard and Poor's, Fitch, and Moody's, were told to contact the Office's leadership on Gmail and Yahoo accounts. The Central Bank's own operational manual for the Office was sent to a Gmail address.

The record also disposes of the suggestion that the transition was rushed on the Central Bank. It was the Ministry of Finance, in a letter of the 13th of April last year, that requested access to the National Resource Management system for foreign debt servicing. It was the Treasury Secretary himself who set the accelerated takeover schedule, and did so, according to the same record, even after the Director-General of the new Office had flagged that the regulations governing it were not ready.

The final accounting is in Annex thirty-three, the payment ledger. Seven fraudulent payment orders were sent. Five were completed, taking USD 2.5 million dollars, plus a further 141,739.95 Australian dollars, into the hands of the fraudsters. One further order was returned by the compliance team at US Bank, in the United States. Another was recalled at the last moment. Of the seven, in other words, only two failed. Neither of those was caught by anything at the Sri Lankan end.

The picture that the Central Bank's submissions now paint of the Ministry of Finance is not one of an institution that came under external attack and was overwhelmed. It is one of an institution that was warned, in writing, that a payment was going to an anti-money-laundering red flag, and that then wrote to the red flag itself to have it confirmed. It is one of a Ministry that, when foreign banks blocked payments to shell companies, re-routed the money rather than pause. It is one where handwritten notes on invoices said "pay immediately," where sovereign creditor communications ran through personal free-mail accounts, where the email server was running out of support before the fraudsters even sent their first message, and where nobody, apparently, read the beneficiary names.

The Central Bank's position, moreover, does not rest on its own submissions alone. Two opinions from the Attorney General, issued in June, went its way. The first, on the 15 of June, ruled that the Central Bank is not an "Institution" under the Financial Transactions Reporting Act, and, in consequence, is not subject to the anti-money-laundering reporting obligations that the Ministry had sought to place at its door.

The second, on the 25th of June, went further, finding that the handover from the Central Bank to the new Debt Management Office had proceeded function by function, on separate dates, and that, in the Attorney General's own words, "upon the proper handing over of any function to the Public Debt Management Office, the responsibility for carrying out such specific function would thereafter be that of the PDMO." On that reading, external debt servicing had already moved to the new office by the 24th of October, three weeks before the first fraudulent payment.

The submissions do not, of course, close every argument. The Attorney General expressly declined to opine, without examining the evidence in detail, on whether any specific function was in fact properly handed over. And the submissions leave open, as the Committee itself did, the question of whether any of this involved internal collusion.

But on the immediate question, of whose email system was compromised, whose invoices were tampered with, whose officers wrote to the fraudster, whose approvals released the money, and whose ledgers show it going out, the answer put on the table today, in the Central Bank's own words and in two opinions from the Attorney General, is one and the same. It was not the Central Bank.

Related recommendation
Hiru TV News | Programmes