What Is Publicly Known
A post appeared on a public cybercrime forum claiming the poster had active access to systems belonging to DFCC Bank, Cargills Bank, and Sri Lanka Customs. The post was written in English and offered the dataset for sale through an escrow service, a mechanism used in criminal marketplaces to guarantee delivery of goods before payment is released.
The post included a freebie sample. Bank account balances belonging to high-balance customers were released publicly as part of this sample, without payment. This is the confirmed data disclosure: balance data was made available before any sale took place. The specific individuals affected are not identified in this report.
A 14-day deadline was issued to the named institutions. The post stated that if no interested parties responded, data samples would be published in stages and sent to bulk email lists of companies across Sri Lanka. The deadline passed without any publicly observable response from the named institutions.
On August 5, 2026, a follow-up post in Russian confirmed the transaction was complete. The sale was described as covering credit card numbers, access to a command and control (C&C) system, and exploits to bypass bank security controls. The post stated the project was closed.
Timeline
Named Targets
What the Sale Confirmation States
The sale confirmation was posted in Russian. Below is the translated content as published, reproduced for documentation purposes.
The use of Russian in the confirmation post is consistent with the actor's apparent origin or operating language. The reference to a C&C (command and control) system is significant: C&C systems are used to maintain persistent access to compromised infrastructure. If the claim is accurate, the buyer received not just data but active tools to continue operating within the affected systems.
What Is Known vs What Is Claimed
Independently Observable
Threat Actor Claims (Unverified)
Why C&C Access Claims Are Significant
Standard data breach incidents typically involve exfiltration of historical data: records pulled from a database and sold. The C&C access claim, if accurate, describes something different: the sale of ongoing access to the compromised infrastructure. A buyer receiving C&C access would retain the ability to issue commands, exfiltrate additional data, or move laterally within the network.
This distinction matters for incident response. If the claim is accurate, closing the transaction does not end the incident. The buyer now holds access tools. The appropriate response from any affected institution is to assume the network is still compromised until a full forensic investigation establishes otherwise.
What Affected Institutions Should Do
Based on the publicly stated claims, affected institutions should treat this as a credible threat requiring immediate investigation, without waiting for independent confirmation of the data's authenticity.
For DFCC Bank and Cargills Bank: engage an incident response team to investigate potential unauthorized access to customer data systems. Audit authentication logs for anomalous access. Review network traffic for C&C communication indicators. Notify the Central Bank of Sri Lanka and CERT.LK. Consider whether customer notification obligations apply under applicable law.
For Sri Lanka Customs: investigate whether employee records were accessed. Review access logs for HR or personnel systems. Notify CERT.LK and the relevant government cybersecurity authority.
For affected customers and employees: if you hold accounts at DFCC Bank or Cargills Bank, monitor for unauthorized transactions and consider placing fraud alerts. If you are a Sri Lanka Customs employee, be alert to phishing attempts using your work information.
Contact for Affected Institutions
CERT.LK (Sri Lanka Computer Emergency Readiness Team) can be reached at incidents@cert.gov.lk for incident reporting and coordination assistance.
The Central Bank of Sri Lanka's Financial Intelligence Unit can be reached through the CBSL website for financial crime reporting.