header logo
Asia asset finance
Mogo Academy
Latest
Expert raises concerns over Finance Ministry’s cybersecurity measures after BEC attack
Apr 25, 202610:15 AM
Expert raises concerns over Finance Ministry’s cybersecurity measures after BEC attack
Mobitel Inner

Cybersecurity expert Asela Waidyalankara states that technical measures are available to prevent incidents such as hackers gaining access to funds, as seen in the reported cyberattack involving a USD 2.5 million Treasury payment.

 

He explained that the cyberattack method used in the incident is known as Business Email Compromise (BEC), a tactic that has affected many private sector institutions.

 

However, Waidyalankara pointed out that because the Central Bank of Sri Lanka (CBSL) has recommended that the domestic banking system obtain ISO 27001—the international standard for Information Security Management Systems—cyberattacks against banks have been minimized.

 

According to him, if an institution such as the Treasury, which bears greater responsibility for the country’s funds than a bank, had implemented similar control mechanisms, the impact of such incidents could have been minimized.

 

Further elaborating, he stated that BEC cyberattacks typically involve intercepting invoices sent by one organization, altering the details, and redirecting payments to fraudulent accounts.

 

Cybersecurity expert Asela Waidyalankara further stated:

 

“The Business Email Compromise (BEC) method was utilized in this cyberattack. This is a common occurrence in the private sector. For example, when an invoice is sent from one organization to another, hackers may intercept it, alter the account details, and redirect the payment to a different account. The concern here is that this involved a financial transaction within a branch of the country’s Ministry of Finance.”

 

He stated that technical tools are available to mitigate such risks and noted that it must be examined whether these measures were properly utilized, whether email systems were up to date, and whether they had been adequately patched. He further observed that there appear to be structural issues within the institution regarding the management and oversight of cybersecurity.

 

“The Central Bank has mandated that Sri Lankan banks obtain ISO 27001 certification, which requires annual external audits. The absence of such standards in an institution like the Ministry of Finance, where national funds are handled, represents a significant shortcoming. While ISO 27001 does not guarantee immunity from cyberattacks, it provides a framework to minimize such risks,” he said.

 

He further added, “Banks are not routinely compromised because they adhere to stringent cybersecurity standards and processes. Given that the General Treasury handles national wealth on a scale greater than that of a typical bank, implementing comparable controls could have potentially prevented this situation.”
 

 

 

 

RelatedNews
MostRead
Mobitel Upahara
VideoStories
President’s recent speech made no reference to actual concerns – MP Dilith

President’s recent speech made no reference to actual concerns – MP Dilith

Ex-SIS chief Suresh Sallay transferred to Cardiology Unit of National Hospital

Ex-SIS chief Suresh Sallay transferred to Cardiology Unit of National Hospital

China's Communist Party marks 105th anniversary; PM Harini praises China's achievements and progress

China's Communist Party marks 105th anniversary; PM Harini praises China's achievements and progress

Colombo EV Motor Show 2026 officially inaugurated

Colombo EV Motor Show 2026 officially inaugurated

Future fuel pricing adjustments under review; Govt aims to provide maximum benefits for consumers

Future fuel pricing adjustments under review; Govt aims to provide maximum benefits for consumers

"No mention of Gotabaya’s name in Easter Attack Comm. reports" Court told during petition hearing

"No mention of Gotabaya’s name in Easter Attack Comm. reports" Court told during petition hearing

Chinese Embassy donates school supplies and dry rations following request by MP Dilith Jayaweera

Chinese Embassy donates school supplies and dry rations following request by MP Dilith Jayaweera

Chikungunya cases surface in addition to dengue outbreak; Public urged to destroy breeding sites

Chikungunya cases surface in addition to dengue outbreak; Public urged to destroy breeding sites

Chaos and uproar in Parliament after Speaker rejects request to debate issues within judicial sector

Chaos and uproar in Parliament after Speaker rejects request to debate issues within judicial sector

Govt. moves to amend laws to remove provisions on marking voters using indelible ink at elections

Govt. moves to amend laws to remove provisions on marking voters using indelible ink at elections

“This is injustice!”: Family appeals to Pope to intervene over continuous detention of Suresh Sallay

“This is injustice!”: Family appeals to Pope to intervene over continuous detention of Suresh Sallay

Dengue cases increasing at an alarming pace; IDH, Kalubowila and Galle hospitals reach capacity

Dengue cases increasing at an alarming pace; IDH, Kalubowila and Galle hospitals reach capacity

Sri Lanka's health system at risk due to surge in dengue cases; PHIs intensify crackdown

Sri Lanka's health system at risk due to surge in dengue cases; PHIs intensify crackdown

SJB-UNP coalition on the cards; Sajith calls for reduction in fuel prices, electricity tariffs

SJB-UNP coalition on the cards; Sajith calls for reduction in fuel prices, electricity tariffs

“Safeguard Suresh Sallay’s health and legal rights” Global Sri Lankan Forum writes to President

“Safeguard Suresh Sallay’s health and legal rights” Global Sri Lankan Forum writes to President

Lassana Flora