Sri Lanka discloses another missing payment, days after hackers stole $2.5M from its finance ministry
Sri Lanka's finance ministry has suffered multiple business email compromise (BEC) attacks resulting in at least $3.125M in stolen funds, with evidence suggesting the breaches may be broader than initially disclosed and potentially linked to compromised payment processing systems. This incident underscores the critical vulnerability of financial institutions to BEC attacks—a top-profit cybercriminal tactic—and demonstrates how inadequate email security and payment controls can expose organizations to massive losses. IT leaders must recognize that traditional perimeter defenses are insufficient; protecting financial transaction workflows requires multi-factor authentication, payment verification protocols, and real-time anomaly detection on critical accounting systems.
