Digitalisation has been touted as a ‘one-stop solution’ for Sri Lanka, promising improved productivity, trade, efficiency, transparency and accountability. However, the recent US$ 2.5 million treasury breach highlights the risks of implementing digital systems without adequate safeguards, expertise and oversight.

The fact that this is reportedly the first known instance globally of funds being stolen directly from a national treasury underscores the seriousness of the case. Beyond the immediate financial loss and its impact on the economy, the incident also risks undermining confidence in Sri Lanka’s digital infrastructure among both citizens and international lenders.

Moreover, the breach comes amid a troubling pattern of cyber related financial crimes including the Rs. 13.2 billion fraud at NDB Bank and the double payment of Aswesuma benefits. And the 625,000 dollars lost by the Department of Posts through a coordinated phishing attack between 2024 and 2025 bears striking similarities to the treasury case.

A growing perception that Sri Lanka is vulnerable to cybercrime could attract both local and international cybercriminal networks.

The arrest of 157 foreign nationals in May, who were suspected of involvement in cyber related offences, suggests that this risk may already be materialising. And the disappearance of French loan documents also suggests that further cyber thefts may be planned.

Criticism has focussed heavily on the incompetence and negligence of the officials responsible. Reports indicate that treasury staff relied on email communications without independent verification procedures, exposing serious weaknesses in accountability and internal controls.

The reliance on outdated systems has drawn widespread criticism, particularly since modern treasury and banking operations typically depend on secure payment gateways directly connected to banking infrastructure.

Given that the government has made the creation of a digital economy a top priority, it is vital that sensitive financial operations are conducted on secure and audited platforms.

However, beyond systemic weaknesses and lackadaisical oversight, these incidents demonstrate that digitalisation is not a panacea for the deep-rooted issues surrounding governance and administration in Sri Lanka.

Until the longstanding issues that have plagued the country since independence – e.g. cronyism, inefficiency, incompetence and corruption – are addressed, the full benefits of digitalisation will continue to elude Sri Lanka.

Share.

Comments are closed.