Scams in Sri Lanka have moved from bad-English emails to convincing SMS in Sinhala, WhatsApp messages with real company logos, and phone calls from people who know your name. The technology got better; the underlying tricks did not. Here is how to recognise them.
The five scams I see most right now
- "Your parcel is held — pay Rs. 150 customs/redelivery fee." SMS with a link to a page that looks like the post office or a courier. The Rs. 150 is bait; the page harvests your card number. Real couriers do not collect fees through a link in an SMS.
- "Your bank account / CEB / SLT account will be suspended — verify now." The link leads to a copy of the bank's login page. Banks in Sri Lanka will never send a login link by SMS. Type the bank's address yourself or use the app.
- "You have been selected for a part-time job — earn Rs. 5,000 a day liking videos." Starts with small real payments to build trust, then asks you to "invest" to unlock bigger tasks. Every rupee invested is gone.
- Fake buyer / fake Fiverr-style client — "I want to order but please chat on Telegram" or "I'll pay via this link". Anyone moving you off the platform to pay is stealing from you.
- The "bank officer" call — knows your name and last four card digits (leaked from some breach), says there is a suspicious transaction, and asks for the OTP "to cancel it". The OTP authorises the transaction. No bank employee ever needs your OTP.
The 10-second checks
- Press and hold the link (do not tap). Look at the real address.
slt-bill-pay.xyzis not SLT.combank-secure.infois not Commercial Bank. Real Sri Lankan institutions use.lkor their well-known.com. - Urgency is the tell. "Within 24 hours", "immediately", "account will be closed" — legitimate organisations do not threaten you by SMS.
- Check the sender. Bank SMS come from a named sender ID (e.g., a bank's name), not a random 07x number. Emails: look at the actual address, not the display name.
- Never share an OTP. Not with a caller, not in a form, not with "customer support" on WhatsApp. The only place an OTP goes is the app or website that you opened yourself.
- Money moving off-platform = scam. Marketplace buyers, freelance clients, rental deposits — the moment they insist on a "different way to pay", walk away.
If you already clicked or paid
- Card details entered: call the bank's hotline (the number on the back of the card) and block the card immediately. Minutes matter.
- Password entered on a fake page: change that password everywhere you used it, and turn on two-factor authentication.
- Installed an APK from a link: uninstall it, then change your banking password from a different device. Some fake apps read your SMS to capture OTPs.
- Report it: Sri Lanka CERT (cert.gov.lk) and the bank's fraud line. Reports help take the pages down before the next person clicks.
Protect the older people in your family
Most losses I hear about are parents and grandparents. Set their phones up with: SMS spam filtering on, Google Play Protect on, "install from unknown sources" off, and one rule they can remember — "If it asks for money or an OTP, call me first." That single rule prevents almost everything above.
Need help with this?
I do this for a living — for businesses in Sri Lanka and clients worldwide. Tell me what you are dealing with.
Comments (0)
// no comments yet — start the conversation
Leave a comment
Comments appear after moderation.