:

SRI LANKA INVESTIGATES $2.5M FINANCE MINISTRY HACK

SECURITY DESK1 MIN READ
THU, APR 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Sri Lanka's government is investigating a cyberattack that resulted in the theft of $2.5 million from the Finance Ministry's systems. Treasury Secretary Harshana Suriyapperuma confirmed the breach on Thursday.

The hack represents a significant security incident for Sri Lanka's financial infrastructure. Attackers gained unauthorized access to the Finance Ministry's computer systems and successfully extracted the funds. Treasury Secretary Suriyapperuma disclosed the breach, indicating that authorities have launched a formal investigation into the incident. Details regarding the attack method, timeline, and the specific vulnerabilities exploited remain under investigation. The incident highlights growing cybersecurity risks facing government institutions in the region. Sri Lanka joins numerous countries grappling with sophisticated cyber threats targeting public sector financial systems. No additional details about recovery efforts or potential attribution have been released. The investigation is ongoing.

■ SOURCES

Bloomberg Tech

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability. The flaw was previously flagged as under active exploitation in April.

1H AGOSecurity Desk

Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11, citing widespread abuse by cybercriminals. The tool is being eliminated from Windows 11 versions 24H2 and 25H2.

4H AGOSecurity Desk

Israel has established a fabricated think tank apparently designed to influence AI chatbot outputs and shape how these systems respond to queries about Israeli policy. The scheme highlights vulnerabilities in how large language models source and validate information.

8H AGOAI Desk

A threat actor claims to have stolen employee databases from Microsoft Azure infrastructure across multiple Fortune 500 companies using compromised credentials. The stolen records are now being offered for sale.

16H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.