134% Surge, And That’s Just What Got Reported
Let’s start with a number that should stop you in your tracks.
In 2025, Sri Lanka’s banking sector saw a 134% surge in cybersecurity complaints. Over 12,650 incidents were officially reported.
But here’s the thing: authorities believe the real number is somewhere between 38,000 and 63,000.
That’s not a typo. Most fraud simply never gets reported.
This isn’t some distant threat we can worry about tomorrow. It’s happening right now. And the fraud of 2026 looks nothing like the fraud we dealt with in 2020.

This Isn’t Your Parent’s Banking Fraud
Remember when fraud meant fake documents, stolen credit cards, and the occasional phishing email?
That world is gone.
Today’s fraudsters have something far more dangerous. They have AI.
Agentic AI – autonomous systems that can think, plan, and execute complex tasks, could slash the cost of running a scam by 90% within two years, according to Boston Consulting Group. The volume of attacks could double, or even triple.
Here’s what that looks like in practice: 80% of financial institutions have already encountered attacks using agentic AI. And 81% of fraud professionals report increasing fraud attempts at their organization up from 71% in 2025.
Meanwhile, there’s another threat quietly growing in the shadows.
Synthetic identity fraud – where criminals create entirely new identities using a mix of real and fabricated information is emerging as the defining fraud threat of 2026. Global losses now approach $20–40 billion annually. It’s the fastest-growing financial crime threat in the world.
These aren’t just global statistics. These threats have already arrived in Sri Lanka.
The NDB Fraud: A Wake-Up Call
You’ve probably heard about the NDB fraud. Rs. 13.5 billion. Confirmed by Deloitte.
But let me tell you what really bothers me about this case.
No audit had been conducted on the bank’s general ledger account since 2022.
Think about that. A bank. A general ledger account. No audit for nearly four years.
And during that time:
- 900 accounts were flagged as suspicious
- 26,108 Telegraphic Transfers were made through 227 accounts in 13 banks
- 105 shell companies were registered by 55 individuals registering a company, sending money abroad within six months, closing it, and registering another under a different name
These were not sophisticated hackers breaking through firewalls. This was one person, allegedly, moving money through a system that had no real-time monitoring, no segregation of duties, and no proper audit trail.
This is not a failure of one bank. This is a systemic failure of the entire financial system’s control architecture.

And Then the Treasury Got Hit
In April 2026, a $2.5 million cyber fraud hit the Treasury’s External Resources Department.
Let me be clear about something: This was not a sophisticated hack.
The fraudsters simply compromised an email account and redirected a government debt repayment. A sovereign debt repayment. Diverted through an email.
The funds left the country. The damage was done. Four senior Finance Ministry officials were suspended pending a disciplinary inquiry.
This should terrify everyone. If government treasury systems can be compromised through email, what does that say about the rest of us?
The President’s Revelation: $1 Billion Lost
President Anura Kumara Dissanayake revealed that Sri Lanka lost nearly US$ 1 billion in foreign exchange due to fraud involving the banking system.
Parliament’s Committee on Public Finance is now questioning Central Bank officials over this revelation. MP Ravi Karunanayake has described the matter as a “systemic collapse of the country’s entire banking system”
Why This Keeps Happening
Look, I’ve been in this industry long enough to know that most fraud isn’t about malicious intent. It’s about architectural failure.
Here’s what I mean:
- Email-based authorisation for high-value transfers seriously?
- Manual verification processes that rely on humans catching errors
- Audit functions designed for a world with far fewer transactions
- Insufficient real-time anomaly detection you only find out something is wrong when it’s too late
- No real-time data integration between foreign payment records and actual import data
These are not people’s problems. These are system problems.
And system problems don’t get solved by investigations. They get solved by redesigning.
What Modern Fraud Defense Actually Looks Like
Let me paint a picture of what proper fraud defense looks like in 2026:
Agentic AI can enable banks to detect suspicious activity, help customers exit scams quickly, and preserve trust when incidents occur.
Real-time anomaly detection can flag suspicious transactions before they leave the country. Not after. Before.
Advanced identity verification can tell the difference between a real customer and a synthetic identity a “digital ghost” that doesn’t actually exist.
Automated audit trails make it impossible for an account to go unaudited for years.
Segregation of duties built into the system, not just written in a policy manual that nobody reads.
This isn’t science fiction. This is available today. From premium, enterprise-grade vendors that have been doing this for decades.

Here’s the Hard Truth
The fraudsters are using AI. They have shell companies. They have synthetic identities. They have deepfakes.
Your defenses were built for yesterday’s threats.
Cheap, legacy systems cannot keep up with AI-powered fraud. They cannot detect synthetic identities. They cannot flag suspicious patterns in real time. They cannot generate an audit trail when CBSL comes knocking with a 2-hour reporting deadline.

Shehani Dharmarathna – Solutions Engineer [BFSI]
