Officials at the Department of External Resources processed the controversial US$2.5 million payment to a fraudulent entity without verifying the original loan agreement or conducting basic due diligence, the Criminal Investigation Department told the Colombo Fort Magistrate’s Court on Wednesday, in the most detailed account yet of how the heist was executed.

CID investigators told Magistrate Pasan Amarasekara that the payment was executed solely on the basis of an emailed invoice purporting to come from Export Finance Australia, the Australian sovereign creditor whose communications channel was compromised. The disclosure crystallises the procedural failure at the heart of the case.

All relevant data from the server system connected to the transaction has now been extracted, the CID said, and four compact discs containing the digital records have been prepared for advanced forensic analysis. The court approved the CID’s request to forward the material to the Computer Forensics Division of the University of Colombo for detailed technical examination.

The investigation has so far recorded statements from 42 individuals.

The CID also presented a copy of the post-mortem report of Ranga Nishantha Rajapaksha, an Assistant Director at the Department of External Resources who had been suspended in connection with the incident and later died. The Attorney General’s Department is expected to formally represent the case in upcoming proceedings.

The next hearing has been fixed for July 8.

The disclosures deepen the procedural narrative around what is now Sri Lanka’s largest disclosed state-sector cyber fraud. The case has been on the parliamentary docket since May and was the subject of an opposition demand for a Parliamentary Special Committee. The Central Bank has also moved to tighten fraud-prevention controls since the breach. The original disclosure of the foreign-debt-route fraud remains the anchor article for the case.