Sri Lanka’s Treasury had been operating an outdated email system since 2019, the Committee on Public Finance (COPF) has revealed, in a disclosure that sharpens questions over how a USD 2.5 million cyber theft from the Treasury was able to occur.

The finding emerged during COPF’s inquiry into the fraud, in which officials were questioned over the incident, NewsFirst reported. The committee had met on several occasions in recent months to examine the case, but details of those discussions were withheld from the media because they involved highly sensitive information relating to the country’s public finances.

COPF Chairman Dr. Harsha de Silva presented the committee’s final investigation report to Parliament on Friday (July 11), concluding its parliamentary oversight of the incident.

The USD 2.5 million was diverted early this year after fraudulent instructions were sent through a compromised email channel used for a foreign debt repayment, with the attempted misdirection detected during a separate payment to India. The affair has since run on multiple tracks — a CID forensic investigation, Central Bank scrutiny and the COPF’s own examination — with the government insisting the loss should be treated as a cybercrime rather than a debt default.

The revelation that the Treasury’s email infrastructure had gone unmodernised for roughly six years points to a structural weakness at the heart of the state’s payments architecture, and is likely to renew calls for a wider audit of government IT systems.