ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Sri Lanka government loses vital email data in a major ransomware attack

The Sri Lankan government’s email network suffered a major ransomware attack that wiped off data from thousands of email accounts, including those belonging to top government officials.Government officials told local media agencies that the ransomware attack took place on 26th August and affected approximately 5,000 email accounts with the gov.lk email domain.Threat actors also targeted the government’s Lanka Government Cloud (LGC) system and encrypted the data stored in the servers along with online backups.According to Mahesh Perera, the head of Sri Lanka’s Information and Communication Technology Agency (ICTA), the IT team was able to restore LGC within 12 hours of the incident, but LGC did not have backups from May 17 to August 26, which meant that data from all the affected accounts were wiped off for that period.Sri Lanka Computer Emergency Readiness Team and Coordination Center (CERT|CC) has started investigating the ransomware attack and said that it is trying to recover the lost data.According to local media, ICTA suspects that the threat actors infiltrated the systems by exploiting an outdated Microsoft Exchange 2013 software. While Microsoft no longer supports the software, it is still used by the Lanka Government Network (LGN), a critical network used by prominent government entities including the Cabinet Office, presidential officials, the Ministry of Education and the Ministry of Health.Government officials have, however, said that they wanted to upgrade the software in 2021 but couldn’t do so due to budget constraints.According to media reports, the Sri Lankan Government has decided not to negotiate with threat actors or give in to their ransom demands. While the identity of the hackers is still unknown, officials believe the cyber security incident was carried out by the infamous LockBit Ransomware gang or the notorious Russian-speaking BlackCat ransomware group.ICTA confirmed that it is taking steps to improve the LGC’s security features to avoid such an attack in the future. This includes implementing daily offline backups and updating the email application to the latest version.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543