- Digital payments improve convenience, transparency, revenue tracking
- Govt. websites could be the weakest link, rather than central payment infrastructure
- Lookalike websites, fraudulent links pose risks to unsuspecting users
- Public awareness urged as GovPay’s reach continues to expand
Sri Lanka’s expanding reliance on digital payments for Government services highlights the importance of platforms like GovPay, which were launched to make public sector payments more convenient, transparent, and efficient.
As more Government agencies and services adopt the platform, the volume and significance of transactions and services processed by the system are also growing.
GovPay was officially launched on 7 February 2025, and the platform has since expanded further.
However, even with the established security standards and safeguards in place, the expansion of a centralised digital payment infrastructure raises cybersecurity concerns, as the ecosystem includes not only the payment platform but also a larger network of Government websites, systems, and users.
Speaking to The Sunday Morning, officials and cybersecurity experts discussed GovPay’s digital architecture, the security standards governing the platform, and the potential risks associated with its growing use for Government payments.
LankaPay: Primary operational and technology partner
The GovPay digital payment platform operates on infrastructure managed by LankaPay and adheres to international payment security standards, according to LankaPay, which oversees the platform’s digital architecture, transaction processing, and security.
LankaPay Chief Executive Officer Channa de Silva said that GovPay was operated through a central system managed by LankaPay, allowing citizens to make Government payments via internet banking, mobile banking, and fintech applications. “It is very simple. Basically, any enabled app from internet banking, mobile banking, or fintech can be used,” he said.
Users selecting the GovPay option on a participating application can select the relevant Government department and service, enter the required amount, and make the payment. The payment is then sent to the account of the relevant Government department and the customer receives an electronic receipt.
De Silva stated that Government institutions had access to a central portal through which they could view payments received. Once the department verifies with the relevant bank that the payment has been received, GovPay sends an SMS notification to the customer confirming that the payment has been received by the department.
“This is a central facility to ensure that customers do not have to resort to using one particular app or website. They can use whatever mobile banking, internet banking, or fintech app they are already using in order to make the Government payment,” he added.
On the storage of GovPay data, de Silva said that the system was operated by LankaPay and that the data was stored within its central system.
He stated that GovPay operated under the relevant internationally recognised standards. “In relation to security, we have Payment Card Industry Data Security Standard (PCI DSS), which is the international standard for the payment card industry, as well as ISO 27001. We also comply with guidelines issued by the Central Bank of Sri Lanka (CBSL),” de Silva said.
He further explained that LankaPay operated under the CBSL and was an authorised entity facilitating financial transactions within the banking and financial ecosystem.
“LankaPay comes under the Central Bank and is the authorised entity that carries out financial transactions within the banking and financial ecosystem. It also facilitates all the interbank transactions like bulk payments and others,” he added, explaining that the CBSL had regulatory authority concerning the stability and security of a financial system, while LankaPay operated the central system used by banks and other institutions to facilitate payments.
LankaPay Chief Manager – Marketing Wayomi Gunathilaka said that GovPay was a collaborative initiative between LankaPay and GovTech Sri Lanka under the guidance of the Ministry of Digital Economy. She added that LankaPay served as the primary operational and technology partner for GovPay, with responsibility extending to its digital architecture and infrastructure.
“Managing the GovPay digital architecture and infrastructure is LankaPay’s responsibility. Processing the transactions and ensuring platform security also falls under LankaPay’s purview,” she said.
Furthermore, de Silva stated that LankaPay’s wider payment infrastructure also connected with international payment networks including India’s Unified Payments Interface (UPI), Alipay, and WeChat, allowing tourists to make payments in Sri Lanka through their respective applications.
“We facilitate payments by tourists through our network. A tourist coming to Sri Lanka can use our network to make a payment using their apps as well. This is a part and parcel of the whole ecosystem of LankaPay,” he said.
GovTech Sri Lanka has taken over the role previously held by the Information Communication Technology Agency (ICTA) in relation to GovPay, according to a GovTech official who wished to remain anonymous.
The official said that ICTA was currently in the process of being wound down, with its functions being taken over by GovTech Sri Lanka.
Significance of GovPay
Meanwhile, speaking to The Sunday Morning, cybersecurity expert and Digital Trust Alliance (DTA) President Lakmal Embuldeniya highlighted the benefits and efficiency of a centralised digital payments system.
Embuldeniya said that digital payment platforms such as GovPay were important not only because they made Government payments more convenient, but also because digital transactions created traceable records of the movement of money.
“The number one factor is convenience; you don’t have to carry cash. Whenever you have a phone with you or perhaps some form of access to the internet, you can simply make the payment,” he said.
He added that the digitalisation of Government payments could also improve revenue collection and decision-making, particularly at the Local Government level, by making payment information easier to track. According to him, digital records could allow authorities to identify payment patterns and determine which areas or services are seeing lower levels of revenue collection.
Embuldeniya also highlighted the importance of GovPay as a common payment mechanism for Government institutions that may otherwise have to develop separate systems and establish individual connections with payment gateways.
“Rather than taking Local Government authorities and other Government organisations through a very cumbersome process of getting into payment gateways, this web interface is a very simple mechanism whereby they can make it available for customers or citizens to make their payments,” he said.
Cybersecurity risks
While GovPay operates within established payment security frameworks, cybersecurity risks could emerge through the websites and users connecting to the platform, according to Embuldeniya.
He said that the security of the wider ecosystem was a key concern, particularly where Government institutions used their own websites to direct citizens towards GovPay. He said that even if the central payment infrastructure was properly secured, a compromised Government website could potentially be used to redirect users to a fraudulent payment page.
“If someone can social engineer the organisation and change the bank information and such details, then automatically third parties such as hackers would be able to route the payments towards them,” he claimed.
He identified the human element as one of the most vulnerable points, arguing that citizens and some personnel operating Government systems may not necessarily have sufficient awareness to identify fraudulent activity.
Embuldeniya also warned of the possibility of attackers creating websites or payment pages that closely resembled legitimate Government or GovPay pages. “Somebody could build a website of a similar design and make it available as the payment link; it would then be a clone,” he argued.
He asserted that this risk could be particularly significant for smaller local authorities whose websites may not have the same level of security resources as major financial institutions.
The DTA President said that users could potentially be deceived into clicking a fraudulent payment link if an attacker compromised a Government website or otherwise presented a convincing imitation of a legitimate payment page.
“From the perspective of people, process, and technology, people would be the most vulnerable,” he said, stressing that the concern was not necessarily with the security of the underlying payment processing infrastructure itself, but with the points at which citizens interacted with the system.
“What LankaPay does is provide an URL and that URL is put into a website. That website will allow customers to pay. But unfortunately, if someone were to compromise that particular website and introduce a similarly designed page, such as something similar to the GovPay web URL, that would become a risk,” Embuldeniya said.
Therefore, he added that public awareness needed to form part of the security strategy alongside technical safeguards. “No such education awareness has taken place,” he said, referring to the need for users to recognise legitimate GovPay links and avoid fraudulent alternatives.
Furthermore, he pointed towards a more sophisticated form of phishing involving lookalike web addresses using Unicode characters. Unicode allows computers and websites to represent characters from different writing systems, and Embuldeniya said that visually similar characters could potentially be used to create deceptive URLs.
As an example, he explained that a fraudulent URL could use a character from another alphabet that visually resembles an English letter, making it difficult for an ordinary user to distinguish the fake address from the legitimate one. “For example, the letter ‘O’ cannot be distinguished from the Russian character ‘O’ at a glance. They look the same, but they have different Unicode values,” he explained, stressing the scale of the potential awareness challenge.
The scale of the platform meant that maintaining security would require attention not only towards the payment infrastructure, but also towards the websites, applications, personnel, and citizens that formed part of the wider ecosystem, Embuldeniya highlighted.
“The risk with GovPay risk lies in users, especially because of how people operate. Process-wise, I do not see much of an issue. But from a technology perspective, there are many things that hackers can do to fool people into clicking a wrong link and making a payment,” he said.