That is his own word, right? Simply put, this individual is admitting that he is keylogging.
"දැන් ගෙදරකට කවුරුහරි ඇවිල්ලා යම්කිසි භාන්ඩයක් හොරකම් කරගෙන ගියා නම්, අපි දන්නවා උදේ නැගිට්ට පස්සෙ මොක්ද්ද මේ ගෙදර තිබ්බ දේ හොරකම් කරගෙන දේ කියලා. TV එක නැත්තං අපි දන්නවා TV එක තමයි නැත්තෙ කියලා.... හැබැයි ඩේටාවල වැඩේ තියෙන්නෙ ඩේටා යම්කිසි දෙයක් අරගන්න ඒක එතනින් නැති කරන්නම අවශ්ය නෑ. කොපි එකක් ගන්න පුලුවන් සරලව.... ඒ නිසා ඇත්තටම අපිටත් ප්රහෙලිකාවක් වෙලා තිබුනා ඒ කරපු කෙනා එයා ගත්ත ඩේටා ටික එලියට දානකම් මොනාද මෙයා ගත්තෙ කියන එක අපිත් දැනුවත් නැතුව හිටියෙ." - ධනික පෙරේරා
එතකොට දැන් මුන් මිනිස්සුන්ගේ data තියාගන්නෙ පොත්වල ලියලද බං?
"දැන් ගෙදරකට කවුරුහරි ඇවිල්ලා යම්කිසි භාන්ඩයක් හොරකම් කරගෙන ගියා නම්, අපි දන්නවා උදේ නැගිට්ට පස්සෙ මොක්ද්ද මේ ගෙදර තිබ්බ දේ හොරකම් කරගෙන දේ කියලා. TV එක නැත්තං අපි දන්නවා TV එක තමයි නැත්තෙ කියලා.... හැබැයි ඩේටාවල වැඩේ තියෙන්නෙ ඩේටා යම්කිසි දෙයක් අරගන්න ඒක එතනින් නැති කරන්නම අවශ්ය නෑ. කොපි එකක් ගන්න පුලුවන් සරලව.... ඒ නිසා ඇත්තටම අපිටත් ප්රහෙලිකාවක් වෙලා තිබුනා ඒ කරපු කෙනා එයා ගත්ත ඩේටා ටික එලියට දානකම් මොනාද මෙයා ගත්තෙ කියන එක අපිත් දැනුවත් නැතුව හිටියෙ." - ධනික පෙරේරා
එතකොට දැන් මුන් මිනිස්සුන්ගේ data තියාගන්නෙ පොත්වල ලියලද බං?
What He Is Saying (The Surface Meaning)
He attempts to explain the data theft by contrasting it with a physical theft (like a TV being stolen from a house).
Physical Theft: When an item is stolen, the owner immediately knows that it is missing and what specifically is missing (e.g., the TV).
Data Theft: With data, the original isn't "lost." Instead, a "copy" is taken.
His Argument: Because of this, he claims that until the hacker publicly released the stolen data, the company itself did not know what was taken. He states it was a "puzzle" (pr-hēlikāvak) for them as well.
Reading Between the Lines (The Implied Meaning)
This statement can be interpreted as an attempt to evade responsibility. What he appears to be "hiding" are the serious weaknesses in the company's technical security systems and internal processes.
1. "We also didn't know what was taken"
This is a very serious admission for a technology company, especially one that handles user data. Any modern, secure system should have robust monitoring and logging.
What this hides:
A lack of adequate logging systems: They should have systems that monitor and alert when large amounts of data are being accessed or moved (known as data exfiltration).
No internal visibility: His statement implies they had no way of tracking which databases, which tables, or which files the hacker accessed.
This indirectly confirms your allegation that the data was "stored in an unsafe manner." If the data had been properly encrypted, with strict access controls and all access attempts logged, they could not claim "we don't know what was taken." They would have a log of the intruder's every move.
2. "A copy of data can be taken simply"
He states this as a simple fact about data, but in doing so, he glosses over the company's core responsibility.
What this hides:
It is the company's job to ensure that a copy cannot be taken "simply."
This implies a lack of fundamental security measures like Multi-Factor Authentication (MFA), strict access controls, and encryption at rest.
His use of the word "simply" is a subtle, perhaps unintentional, admission that the hacker's job was made easy.
3. "Until he put it out (released it), we didn't know"
This is a public relations (PR) strategy. It's used to justify the company's silence or lack of transparency in the immediate aftermath of the incident.
What this hides:
They are trying to "hide" not necessarily the breach itself, but the scope of the breach and, more importantly, how completely "in the dark" they were about their own system's failure.
By claiming "it was a puzzle for us," he frames the company as a fellow victim rather than the responsible party that failed to secure the system. This evades accountability.
Analysis Conclusion
When analyzing this quote against specific allegations:
Unsafe Storage: This is strongly implied. Admitting that you have to wait for a hacker to publicly release your data to find out what was stolen is a massive admission of having poor security, monitoring, and logging practices.
Cover-up (Tried to Hide it): The quote does prove it's an attempt to justify their lack of transparency ("We couldn't tell you what was stolen because we didn't know"). What they were truly trying to hide was the company's internal technical incompetence and the extent of their security failure.
------
Post added on Nov 16, 2025 at 1:45 PM