

Sri Lanka Police have uncovered a major financial fraud operation involving fake websites and a malicious mobile application posing as an official service of SriLankan Airlines.

According to the Police Media Division, scammers contacted individuals via WhatsApp and directed them to download a fake app named SriLankan.apk through fraudulent websites.
Investigations revealed that the app operates as a banking trojan, allowing criminals to gain remote access to victims’ mobile devices and extract sensitive personal information.
Police stated that the scheme enables fraudsters to capture One-Time Passwords (OTPs), banking credentials, and biometric data such as fingerprints and facial recognition details.
Using this stolen information, the suspects access victims’ banking apps and carry out unauthorized fund transfers to other accounts.
Authorities have also identified several telephone numbers linked to the operation and warned the public to remain vigilant.
The Police emphasized that many victims are deceived by promises of quick financial rewards and urged citizens not to fall prey to such scams.

