:

SRI LANKA CONFIRMS $3M IN CYBER THEFT

SECURITY DESK1 MIN READ
SAT, MAY 9, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Sri Lanka's government disclosed a second major cybersecurity breach within days, revealing combined losses exceeding $3 million. The incidents add to the nation's financial troubles as it recovers from its 2022 debt crisis.

The finance ministry confirmed a $2.5 million theft in one attack, followed by the discovery of another missing payment shortly after. The dual breaches underscore vulnerabilities in the country's digital infrastructure at a critical economic moment. Sri Lanka faces mounting pressure to strengthen cybersecurity protocols across government agencies. The timing is particularly problematic, as the nation continues managing fallout from its severe 2022 debt crisis, which left its economy destabilized. Authorities have not yet disclosed details about the attackers' methods or identities. The breaches highlight growing cyber threats targeting government financial systems in developing nations, where resources for defense may be limited. No statement has been released regarding recovery efforts or enhanced security measures being implemented.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Austrian and Albanian authorities dismantled a major cryptocurrency investment fraud operation that defrauded victims worldwide of over €50 million. The criminal network ran large-scale scams targeting investors seeking cryptocurrency returns.

JUST NOWIndustry Desk

cPanel and WebHost Manager (WHM) released an emergency update to fix a critical authentication bypass vulnerability affecting nearly all versions. The flaw could allow attackers to gain unauthorized access to hosting control panels.

2H AGOIndustry Desk

Palo Alto Networks reports that frontier AI models completed security analysis in three weeks that would normally take a year of manual penetration testing, while achieving broader coverage.

2H AGOAI Desk

A compromised third-party OAuth application became a direct entry point into Vercel's infrastructure, affecting downstream customers. The incident reveals how shadow AI tools and OAuth sprawl create systemic security vulnerabilities.

3H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.