The Anatomy of a Digital Heist: How Sri Lankans Are Being Tricked Out of Their Savings.

The Anatomy of a Digital Heist: How Sri Lankans Are Being Tricked Out of Their Savings.

It starts with an SMS claiming a CCTV camera captured your vehicle exceeding the speed limit, directing you to a link to pay the fine on a portal that looks identical to the official GovPay platform. Or perhaps it is an urgent WhatsApp message from a contact claiming she lost her phone on a bus and desperately needs a transfer to buy a replacement. In modern financial
crime, the attack vector is rarely a breach of vault security; it is the human on the other side of the screen.

Across Sri Lanka, fraudsters rely on social engineering playbooks to harvest One-Time Passwords (OTPs), personal identification numbers, and banking credentials. Scammers exploit everyday human emotions—fear of a legal penalty, empathy for a friend in distress, or greed sparked by AI deepfake videos of public figures endorsing fake investment returns. Once an OTP is shared over a phone call or entered on a spoofed website, account balances can be drained in seconds. Banking systems operate with continuous multi-layer encryption, real-time

fraud detection engines, and strict regulatory oversight. However, when a user is tricked into sharing access keys, security controls are bypassed. Recognizing these playbooks before the next fraudulent link arrives remains the most critical public service awareness tool.