Experts say hacked data shared by Anonymous from various Sri Lankan governmental and other websites has put regular citizens at severe risk of cybercrimes
Leaked data by the hacker collective has put regular Sri Lankans at severe risk of cybercrime. — • COLOMBO, SRI LANKA Tweets: @martijn_grooten , @mskidchaos , and @restofworld Tweets: Martijn Grooten / @martijn_grooten : Intention without strategy is chaos. Here's @dimuthudca writing about Anonymous leaking data of regular Sri Lankans, as it tried to support the protests in the country https://restofworld.org/... @mskidchaos : At what point do we decide that thoughtful consideration before deploying any technological solution is better than a “move fast & break things” attitude? When is the value of other people's lives more important than the value of our own heroism? https://restofworld.org/... @restofworld : Sri Lankans question Anonymous's decision to launch #OpSriLanka strike, which may have harmed regular citizens more than President Gotabaya Rajapaksa https://restofworld.org/...
Context & Ripple Effects
Anonymous dumped data stolen from Sri Lankan government and other websites in a show of support for the protest movement against Gotabaya Rajapaksa's government — but security researchers including Martijn Grooten say the dump exposed ordinary citizens, not officials, to fraud and identity theft. It lands in a country whose information environment is already strained: past coverage found that blocking social networks after terrorist attacks backfired in Sri Lanka because official sources were unreliable, leaving citizens dependent on informal channels.
That same fragile ecosystem is why local groups matter here — the research collective behind Watchdog's fact-checking app has been using open-source data to investigate the country's crises, and now faces a wave of leaked personal data that muddies rather than clarifies the picture.
First-order effects
- Sri Lankan citizens whose personal data appeared in Anonymous' dump face immediate exposure to phishing, identity theft, and account takeover, with no clear remediation path from the breached agencies.
- The Sri Lankan government bodies whose sites were hacked are forced into incident response during an ongoing political crisis, compounding their credibility problem with protesters.
Second-order effects
- Fraudsters gain a ready-made dataset of verified personal details from government systems, lowering the cost of targeted scams against Sri Lankans — the same downstream-abuse dynamic seen when hacked law enforcement emails are used to fire off Emergency Data Requests that providers quickly comply with.
- Civil society verifiers like Watchdog take on extra burden distinguishing legitimate leaked records from forged ones, since raw dumps become raw material for disinformation as easily as for accountability.
Third-order effects
- If the pattern holds, hacktivist 'support' leaks become a recurring source of collateral harm to the very populations they claim to defend — echoing earlier findings such as the Lebanon-linked trove of passwords and eavesdropping files left exposed online — pushing researchers toward norms for responsible handling of breached state data.
- Governments facing unrest gain a ready argument that external hacker intervention endangers citizens, potentially hardening controls on the open information channels Sri Lankans have relied on when official sources fail.
The trend: Hacktivist data dumps are shifting from symbolic strikes against governments to indiscriminate exposures that put bystander civilians at risk, forcing a reckoning over disclosure norms in politically charged breaches.