Sri Lanka — Cyber Threat Profile
Sri Lanka CERT|CC, founded in 2006, is the country's national cyber incident response centre and a member of FIRST and the Asia Pacific CERT; it sits under the Ministry of Digital Economy. Computer offences fall under the Computer Crimes Act No. 24 of 2007, and the Personal Data Protection Act No. 9 of 2022 made Sri Lanka the first South Asian country to enact comprehensive data protection legislation, but the Personal Data Protection (Amendment) Act No. 22 of 2025, published in the Gazette of 31 October 2025, left the substantive provisions on processing, data-subject rights and penalties to be commenced by a ministerial order that had still not been issued as of early 2026. Cabinet approved a National Cyber Security Strategy for 2025-2029 on 14 July 2025, drafted through Sri Lanka CERT with World Bank support and building on the first national strategy implemented from 2019 to 2023, with strategic areas including strengthening the legal and regulatory framework and enhancing cyber security preparedness. Sri Lanka CERT received more than 12,650 complaints relating to cybersecurity incidents and social media misuse in 2025, a large portion of them fake and hacked accounts and financial scams run through social platforms. A ransomware attack on the Lanka Government Cloud, confirmed by the ICT Agency on 11 September 2023, affected all 5,000 gov.lk email addresses including those used by the Cabinet Office and permanently destroyed mail covering 17 May to 26 August 2023 because no backup existed for that window, on a platform running Microsoft Exchange 2013 that Microsoft had stopped supporting on 11 April 2023.- National CERT/CSIRT: Sri Lanka CERT
- Secure Internet servers per 1M people (2024): 448.7 (source: World Bank)
- Internet users (2024): 54.6% of population (source: World Bank)
Threat actors targeting Sri Lanka
Most targeted sectors
Recent claimed incidents
Read the full analysis on IntelFusions