The $2.5 Million BEC Heist: How a Look-Alike Domain Crippled Sri Lanka’s Finance Ministry

Between December 2025 and April 2026, attackers used Business Email Compromise with a look-alike domain to divert $2.5M in sovereign debt payments. Here's the technical breakdown of the attack, why it took 4 months to detect, and what Sri Lankan organizations must do now.


