Sri Lanka

Pension Department Data Breach – Vulnerability Still Exists and Nobody is Fixing It!

️ "No data lost in cyberattack on Pensions Dept, systems restored" – The Department of Pensions
This is an absolutely false statement.

️ The breach likely wasn’t even caused by sophisticated hacking – it’s probably due to EXPOSED PUBLIC API ENDPOINTS that anyone can access.

️ These endpoint are still open, a person with basic IT knowledge can easily write a simple script with just a few lines of code and extract the entire database. This is basic web scraping, not even "hacking".

️ The department has inadvertently created undocumented public API endpoints that expose their entire database to the world.

️ After the initial data dump on the dark web, the department introduced an OTP authentication. However, this OTP implementation is laughably flawed.

️ The OTP is generated on the front end (your browser) and sent to the back end for "verification." It’s like showing you the PIN on screen and then asking you to type it back. This provides zero actual security while creating dangerous false sense of security.

️ Every W&OP scheme member’s complete data has been compromised: Name, Address, NIC, Phone, Photo, Gratuity amounts and Workplace details. Thousands of retired government employees, military, and police families are affected. (Anyone can enter the generated number shown in your browser and access the information.)

️ Pensioners are prime targets for scams. Scammers now have everything needed to target Sri Lankan pensioners. They can call knowing exact ID numbers, addresses, pension amounts, and workplace history.
Tell your parents/grandparents: NEVER share personal info, OTPs, or card numbers with callers – even if they know your details. Hang up and verify independently.

️ Considering the inclusion of military personnel and public data, this should be considered national security emergency affecting the public servants and most vulnerable citizens and security personnel. Every hour of delay puts more lives at risk.

️Someone needs to immediately shut down the Pensions Department login portal (
https://service.pensions.gov.lk/pensionerservices/#/login). Conduct a full security audit and notify all affected individuals at once. immediately.
Note: We came across this over 48 hours ago and reported it to the relevant authorities through multiple independent channels capable of independently verifying the information. However, no action has been taken so far, and the vulnerabilities remain unresolved.
#SriLanka #PensionDepartment #DataBreach

The Sri Lankan Department of Pensions has become the latest victim of the Cloak Ransomware gang. (
https://www.pensions.gov.lk/)

First hinted at on April 2, 2025 as “pe*.lk”

Confirmed on May 26, 2025 with the full domain revealed

Over 617 GB of sensitive data dumped on the dark web.
(2389719 directories, 1340906 files)
This isn’t an isolated attack.
Sri Lanka is being repeatedly targeted — financial institutions, public services, citizen data.
Why are we so vulnerable?

Outdated systems

No proactive cybersecurity strategy

Weak incident response

No geopolitical footing in global cyber defense coalitions
Here’s the truth:
We’ve been spared a massive financial wipeout so far — only because many still don’t use online banking.
But that won’t last. A full-scale money-out op is inevitable if we go on like this. And next time, it won't be just "Data". It’ll be your bank account, and your Identity.
We cannot afford digital amnesia.
It’s time to:
• Modernize — not patch
• Build and retain cybersecurity talent
• Create a national cyber threat intelligence unit
• Join global alliances and share intelligence
We are being watched. We are being tested.

TECHNICAL ALERT:
The 617G+ dump isnt just Scanned PDFs. Inside the exposed config tree are files like tomcat-users.xml likely holding hardcoded admin credentials, and hibernate.cfg.xml containing plain-text database passwords, giving full access to backend data stores. Core Tomcat configs (server.xml, context.xml) expose JNDI paths, internal ports, and context definitions, making the system vulnerable to Remote Code Execution (RCE) via known deserialization exploits. Even worse, the leak includes source code and compiled .class files for live applications, .jsp logic, WAR deployments, and runtime logs (hs_err_pid*.log) — a goldmine for attackers to craft precise payloads based on actual environment variables. There’s also a Solr data directory (/solr-example/data/index/) — suggesting searchable sensitive data was indexed and left exposed.

This isn’t just PII theft — it’s a blueprint of our infrastructure, showing adversaries exactly how the system runs, how it breaks, and how to take it over. If this were a red team simulation, it would rank P1: Total Compromise.

This should trigger a national cybersecurity emergency — . For every dev, sysadmin, or security engineer in the Sri Lankan public sector: assume compromise and act like this was your stack — because next time, it might be. (PS- I didnt access any of these, dont have the time, it's hosted you know where go take a look)

Disclaimer:
This post is not intended to incite panic but to ensure the public is informed about the scale and nature of the attack.
Information and screenshots were taken from publicly accessible sources, including the Cloak ransomware gang’s dark web data dump.
No private systems were accessed, and no illegal activity was undertaken in preparing this post.
The goal is clear: to raise awareness, not fear — and to call for urgent national cybersecurity reform.
#SriLanka #CyberSecurity #DataBreach #CloakRansomware #DigitalRisk #Ransomware #GovTech #Pensions #OnlineBanking #CyberAlert #Infosec #DigitalResilience