Sri Lanka postal cyber heist saw US$626,755 meant for USPS diverted through nine foreign accounts using fraudulent payment instructions.
COLOMBO — Sri Lanka’s Criminal Investigation Department is tracing US$626,755 diverted from international postal settlements into nine external bank accounts after fraudulent electronic payment instructions were allegedly used to redirect funds intended for the United States Postal Service.
Details placed before the Colombo Fort Magistrate’s Court indicate that the Department of Posts did not lose the money through a conventional theft. Instead, investigators allege that fraudulent payment instructions were generated through spoofed electronic communications and acted upon by officials responsible for international postal settlements.
The suspected scheme appears to have unfolded in three stages over roughly two years, beginning with a relatively small transfer before escalating into two major transactions.
An initial payment of about US$900 in 2024 is believed by investigators to have functioned as a test of the payment process.
After that transaction apparently failed to trigger effective detection, significantly larger transfers followed.
Transfers Escalated in 2025
In February 2025, more than US$400,000 was diverted.
A further transfer of nearly US$190,000 followed in October 2025.
Together with the earlier transaction, the diverted payments ultimately totalled US$626,755.
The sequence has placed the Department of Posts’ internal payment controls under scrutiny, particularly over how a small initial transaction could be followed by two much larger transfers without the developing pattern being detected.
Investigators are now examining whether the weakness lay primarily in the electronic communications used by the attackers, in internal verification procedures, or in a combination of both.
Fraudulent Instructions Allegedly Came Outside UPU Channel
International postal settlements are conducted within established institutional arrangements.
The CID informed court that the Universal Postal Union maintains secure communication and account systems for international postal transactions.
Despite those safeguards, the fraudulent payment instructions in this instance were allegedly transmitted through an email address outside the official UPU communication channel.
That detail may prove central to the investigation.
If officials acted on instructions received outside the recognised UPU system, investigators will need to establish what verification procedures were required before the payments were approved and whether those procedures were followed.
The evidence described so far suggests that the vulnerability may not have originated within the international postal system itself, but in how payment instructions were checked and authenticated within Sri Lanka before the transfers were executed.
USPS Alerted Sri Lanka in April 2026
The fraud became known on April 28, 2026, after the United States Postal Service alerted Sri Lankan authorities that expected payments had not reached it despite Sri Lanka having processed the relevant settlements.
By that stage, investigators allege that the diverted funds had already been distributed among nine external accounts.
The CID’s Computer Crimes Division subsequently began investigations under court supervision.
Senior officials of the Department of Posts have provided statements, while computers, server records and communication logs linked to the transactions have been taken into custody as digital evidence.
The Sri Lanka Computer Emergency Readiness Team has also been directed to conduct a forensic examination of the Department of Posts’ digital environment.
Investigation Extends Beyond Sri Lanka
The involvement of the Foreign Ministry indicates that investigators may need assistance from overseas authorities as they attempt to trace the funds and identify those controlling the nine accounts.
Cross-border cyber-enabled financial crime can complicate recovery because account holders, recipient banks and digital infrastructure may be located across multiple jurisdictions.
International cooperation may therefore be necessary to obtain banking information, identify beneficial account holders and determine whether any of the diverted funds can be frozen or recovered.
At this stage, the identities of those allegedly behind the fraudulent communications are not established in the source material.
Nor does the information placed before court determine whether any official within the Department of Posts knowingly participated in the diversion.
Payment Controls Come Under Scrutiny
Beyond the immediate criminal investigation, the case exposes a wider governance problem for government institutions handling large international payments.
High-value transfers cannot depend solely on whether an employee recognises a suspicious email.
Effective financial controls ordinarily require several independent safeguards, including verification of payment instructions, multiple levels of authorisation, transaction monitoring and clear separation between officials who initiate and approve payments.
The three-stage chronology described by investigators will therefore be important in determining whether warning signs were missed after the initial US$900 transaction.
A central question is whether the first transaction created an opportunity to detect the attempted fraud before the much larger transfers were processed in 2025.
Wider Government Systems May Face Review
The US$626,755 loss represents the immediate financial damage identified so far.
A broader concern is whether similar vulnerabilities exist elsewhere in Sri Lanka’s public-sector payment infrastructure.
The forensic examination of the Department of Posts’ systems may help determine whether the incident resulted from compromised accounts, spoofed communications, inadequate verification procedures, weak internal controls or another form of cyber intrusion.
Investigators must also establish how the funds moved through the nine external accounts and whether any portion remains recoverable.
The findings could have implications well beyond the postal service if they reveal weaknesses common to other government payment systems.
For now, the CID investigation continues with the central questions unresolved: who generated the fraudulent instructions, why they were accepted, where the US$626,755 ultimately went and whether stronger controls could have stopped the scheme before the larger transfers were completed.
