Rs. 2.87 Million Vanishes in 14 Minutes: Sri Lanka Banking Incident Raises Digital Fraud Questions
A Bank of Ceylon customer disputes 30 transactions totaling Rs. 2.869 million completed within 14 minutes. BOC says its systems were not breached, raising questions about credential theft, OTP security and digital banking fraud.

A disputed series of digital banking transactions in Sri Lanka has drawn attention to the growing challenge of protecting customers from financial fraud, even when a bank's underlying systems have not been compromised.
A customer of the Bank of Ceylon (BOC) has complained that approximately Rs. 2.869 million was transferred from his account through 30 transactions within just 14 minutes.
According to media reports, the account was maintained at BOC's Baddegama branch and belonged to a retired Sri Lanka Army nursing officer.
The family says the money was part of a Rs. 4.4 million loan obtained against the account holder's pension, reportedly intended to help the family build a home.
30 Transactions in Just 14 Minutes
According to the account provided by the family, the transactions occurred between approximately 1:24 a.m. and 1:38 a.m. on August 14, 2026.
The reported transaction pattern consisted of:
- 28 transfers of Rs. 100,000
- One transfer of Rs. 50,000
- One transfer of Rs. 19,000
Together, the transactions amounted to Rs. 2,869,000.
The family says it became aware of the activity after receiving transaction notifications and contacted the bank's hotline while the transfers were occurring.
They maintain that the transactions were unauthorized.
Complaints were subsequently reported to have been made to law-enforcement and cybersecurity authorities, including the Elpitiya Special Crimes Investigation Unit, the Computer Crime Investigation Division and Sri Lanka CERT.
Bank of Ceylon Says Its Systems Were Not Breached
Bank of Ceylon has publicly rejected suggestions that the incident resulted from a compromise of its banking infrastructure.
According to the bank's statement reported by local media, the transactions were authenticated using the relevant online banking credentials together with One-Time Passwords (OTPs) sent to the customer's registered mobile number.
BOC said the reported transactions were not caused by a compromise, security breach or malfunction of its banking systems or digital banking application.
The distinction is important.
A transaction being successfully authenticated does not necessarily establish who was physically responsible for initiating it. Conversely, a customer's claim that transactions were unauthorized does not establish that the bank's infrastructure was compromised.
Determining exactly what happened would therefore require examination of the relevant authentication, transaction, device, network and communication records.
How Could an Attack Occur Without Hacking the Bank?
This case highlights an important cybersecurity concept: attackers do not always need to hack a bank's core infrastructure to steal money.
Modern financial fraud frequently focuses on compromising the customer rather than directly attacking the financial institution.
Possible attack paths in digital banking environments can include:
Phishing — Victims can be redirected to websites designed to imitate legitimate banking portals, where attackers attempt to capture usernames, passwords and other information.
OTP theft — Criminals may use phishing or social engineering techniques to convince victims to disclose one-time passwords.
Credential theft — Previously compromised usernames and passwords may allow attackers to attempt access to banking services.
Malicious applications — Fraudulent or compromised mobile applications can potentially steal information or abuse permissions granted by users.
Social engineering — Attackers may impersonate bank employees, government officials, police officers or other trusted parties to manipulate victims into providing sensitive information.
Compromised devices or communications — Access to a victim's phone, email, browser or other digital environment could potentially expose information needed to facilitate fraudulent activity.
These are possible attack scenarios in digital banking fraud generally. There is currently insufficient public evidence to conclude that any particular technique caused the BOC incident.
Sri Lanka Faces a Wider Online Scam Problem
The incident comes amid continuing warnings about online financial scams targeting Sri Lankan users.
Sri Lanka CERT has warned the public about schemes involving criminals impersonating trusted organizations and officials.
In one fraud scheme reported by CERT in August 2026, criminals impersonated officials from institutions including the Central Bank of Sri Lanka and the Police Financial Crimes Investigation Division. Victims were pressured into transferring money after being presented with fraudulent claims and forged documents.
Other reported campaigns have used fraudulent SMS and WhatsApp messages, phishing websites and fake payment pages to obtain personal or financial information.
The trend demonstrates why protecting digital banking increasingly requires security controls extending beyond the bank's internal infrastructure.
The Fraud-Detection Question
One of the cybersecurity questions raised by the reported incident concerns transaction anomaly detection.
Thirty transactions reportedly occurred within approximately 14 minutes during the early hours of the morning.
In modern digital banking environments, fraud-monitoring systems can analyze factors such as:
- Transaction frequency
- Transaction amount
- Time of transaction
- Beneficiary history
- Device characteristics
- Login behaviour
- Geographic or network anomalies
- Changes from a customer's normal transaction pattern
Multiple rapid transfers can potentially represent a behavioural anomaly worthy of additional verification depending on the customer's normal activity, the bank's configured controls and other risk indicators.
However, the publicly available information does not establish whether BOC's fraud-monitoring systems generated an alert in this particular case or what risk information was available to the bank at the time.
BOC has previously reported investments in fraud detection and cybersecurity capabilities. Its published reporting has referenced real-time payment tracking and fraud detection as well as technologies including SIEM, Network Detection and Response, Data Loss Prevention, advanced threat protection and Privileged Access Management.
Authentication Is Only One Layer of Security
The incident also demonstrates an important distinction between authentication security and fraud detection.
Passwords and OTPs help verify that someone possesses particular authentication factors.
But attackers increasingly attempt to obtain those factors legitimately from victims through deception rather than defeating the cryptography or security infrastructure protecting them.
This is why banks increasingly combine authentication with behavioural analytics, transaction monitoring, device intelligence and risk-based authentication.
A technically valid login does not automatically mean that the person controlling the session is the legitimate account holder.
What Banking Customers Should Do
Bank of Ceylon has reminded customers not to disclose passwords, PINs, OTPs, card information or other confidential banking details.
Customers should also avoid accessing banking services through links received unexpectedly via SMS, WhatsApp, email or social media.
Instead, banking services should be accessed using the bank's official application or by manually navigating to its verified website.
Users should also:
- Never provide an OTP to someone over a phone call or messaging service.
- Treat urgent requests involving money or banking credentials with suspicion.
- Verify suspicious communications directly with the bank.
- Review transaction notifications immediately.
- Use unique passwords for financial accounts.
- Keep phones and banking applications updated.
- Avoid installing applications from unknown sources.
- Immediately contact the bank if suspicious transactions or login activity is detected.
Sri Lanka CERT provides an incident-reporting hotline at 101 for urgent cybersecurity incidents and maintains an online incident-reporting service.
Investigation Remains Important
At present, the publicly available information presents two important facts that should not be confused.
The affected family maintains that the 30 transactions were unauthorized, while Bank of Ceylon maintains that its banking systems and digital application were not breached and that the transactions were authenticated using banking credentials and OTPs.
Neither statement alone explains how the credentials were obtained, who initiated the transactions or how the money ultimately moved.
A comprehensive investigation could potentially examine login records, IP addresses, device identifiers, authentication logs, OTP delivery records, beneficiary accounts, transaction timestamps and the timing of communications with the bank.
Until investigators establish those details, attributing the incident to a specific cyberattack technique—or to a failure of a particular party—would be premature.
What the incident does demonstrate is a broader cybersecurity reality:
Protecting digital banking is no longer only about preventing hackers from breaking into banks. It is also about preventing criminals from exploiting the people who use them.
Sources
This report was prepared using information published by The Morning Telegraph, Sri Lanka Mirror, Bank of Ceylon statements reported by local media, Sri Lanka CERT public cybersecurity advisories, and Bank of Ceylon's published cybersecurity and digital-banking information.
Related reporting
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters claims it breached FBI systems and stole sensitive data on agents, employees and job applicants, while the FBI investigates unauthorized activity affecting FBIJobs.gov.
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Entries
Gyazo disclosed a major breach exposing 23.62 million user records and metadata for roughly 490 million images, potentially enabling unauthorized access to some uploaded content.
Revolut Data Breach Exposes Passports and Full Transaction Histories After Fake Government Request
Fintech giant Revolut has confirmed a data-security incident in which an unauthorized party obtained sensitive customer information after submitting fraudulent requests that appeared to come from a legitimate government agency.


