SINGAPORE — A cyberattack on a human-resources and payroll platform used by organisations under Singapore’s Islamic Religious Council has disrupted back-office operations and raised fresh questions over the security of some of the most sensitive information an employer can hold: names, salaries, contact information and bank-account details.
The Islamic Religious Council of Singapore, or MUIS, confirmed that a cybersecurity incident affected a human-resource management system operated by Singapore software company Avelogic.
The affected platform, SmartHRMS, is used for functions including payroll, employee records, leave administration, claims and attendance. MUIS said public-facing and government services continue to operate normally and that business-continuity arrangements have been activated for essential HR and payroll functions.
The Singapore Police Force has confirmed that a report was lodged and investigations are underway.
The Personal Data Protection Commission, or PDPC, has also said it is aware of the incident and is investigating the data-breach notification filed in relation to it.
But the central question remains unresolved:
Exactly what employee information, if any, did the attackers manage to remove before the system was locked down?
Avelogic says its latest independent forensic investigation found no evidence of bulk data exfiltration.
That is reassuring.
It is not the same as saying investigators have proven that absolutely no data left the environment.
What happened to SmartHRMS?
Avelogic says confirmed threat-actor activity occurred between August 30 and August 31, 2026.
The company subsequently filed a police report on August 31 and notified the PDPC in its capacity as a data intermediary. On September 3, it engaged cybersecurity firm Black Panda to conduct an independent forensic investigation.
The Straits Times reported that the incident involved ransomware, with hackers encrypting systems supporting payroll and HR functions used by mosques and madrasahs associated with MUIS.
Ransomware attacks typically attempt to deny an organisation access to its systems or files, often by encrypting them, before demanding payment.
Modern ransomware incidents can involve an additional threat: attackers may steal information before encrypting systems and then threaten to publish or sell the stolen data.
That second possibility is particularly important here because payroll systems can contain extraordinarily valuable personal information.
What kind of information can SmartHRMS hold?
Avelogic markets SmartHRMS as an integrated cloud-based payroll and HR system for Singapore employers.
According to its own product description, the platform can manage information including:
- employee biodata and family records;
- salary and payroll history;
- bank information used for payroll;
- leave and medical-leave records;
- educational information;
- workplace incident or disciplinary records;
- claims and employee documents;
- CPF and other statutory payroll information.
That does not mean every affected organisation stored every one of those categories in the compromised environment.
But it explains why a breach of an HR platform receives very different scrutiny from, for example, a temporary outage of a public website.
A payroll database can potentially contain enough information to support identity fraud, phishing, payroll scams or highly targeted social-engineering attacks.
Reports say salary and bank details may have been involved
The Straits Times reported that potentially affected information included staff salary and bank-account details.
Lianhe Zaobao, citing the same reporting, said sensitive details involving employees at dozens of mosques and madrasahs may have been affected, including names, contact details, salaries and bank-account numbers.
MUIS itself has not publicly confirmed the exact categories of information affected.
It has also not disclosed how many employees or organisations were involved.
The council said it would not provide further information while investigations continue.
That distinction matters.
Reports that certain information was potentially exposed should not be turned into a definitive claim that hackers successfully stole those records.
The investigation is still establishing the scope.
Avelogic says investigators found no evidence of bulk theft
Avelogic’s latest public update, dated September 14, offers a more encouraging assessment.
The company says an independent forensic investigation found “no evidence of bulk data exfiltration” based on available Amazon Web Services network telemetry covering the confirmed attack period from August 30 to 31.
It also says core sensitive information within SmartHRMS remained protected by application-layer encryption.
That is a meaningful finding.
But the wording is carefully limited.
“No evidence found” does not necessarily establish that no individual record, credential or smaller volume of information could have been accessed.
It means investigators did not find evidence of a large-scale data transfer in the telemetry they examined.
The full forensic investigation and regulatory review will therefore matter.
Why encryption inside the database matters
Encryption can significantly reduce the usefulness of stolen data when implemented correctly.
Avelogic says key sensitive fields were encrypted at the application layer, meaning certain information was stored in encrypted form rather than readable plain text.
However, whether encryption protects information in a particular breach can depend on several factors, including whether attackers also gained access to encryption keys, application credentials or authenticated sessions.
Avelogic has not publicly provided enough forensic detail to independently determine those questions.
So the correct conclusion at this stage is narrower:
Avelogic says sensitive fields were encrypted, and its forensic investigation has not found evidence of bulk exfiltration.
That is different from declaring the incident harmless.
Payroll operations had to fall back on business-continuity measures
The cyberattack was not only a privacy issue.
It also became an operational problem.
MUIS said affected organisations implemented continuity arrangements to maintain essential HR and payroll functions.
Zaobao reported that some finance personnel could no longer log into the system following the attack and had to urgently handle payroll processing through manual alternatives.
That illustrates one of ransomware’s most disruptive characteristics.
Even if attackers never successfully steal a large dataset, encrypting an HR platform can still stop an organisation from:
calculating salaries,
checking payroll records,
processing leave,
accessing employee information,
or preparing bank-payment files.
For workers, the immediate concern can therefore be very practical:
Will I still get paid on time?
MUIS says continuity arrangements are intended to keep those essential functions running.
Avelogic says it has recovered the latest data set
There has also been a significant development on the recovery side.
Avelogic says it has successfully recovered the latest updated dataset and is rebuilding the service inside a newly provisioned and isolated infrastructure environment.
The company says it is implementing security improvements recommended by forensic specialists before allowing customer access again.
Its target is to make the new system available by September 18, with other components returning progressively thereafter.
Avelogic also says round-the-clock network monitoring is being implemented in the rebuilt environment.
Customers will need to watch for re-registration instructions before regaining access.
The recovery timeline is important because payroll cannot simply stop
HR platforms rarely attract the same public attention as banks, hospitals or government portals.
But they can become mission-critical infrastructure inside an organisation.
Employees can tolerate a leave portal being unavailable for several days.
Missing payroll is very different.
Payroll systems interact with bank files, CPF calculations, tax reporting and employee records.
Avelogic’s own product materials say SmartHRMS supports GIRO payroll files for major banks and automated CPF and IRAS-related processes.
That explains why MUIS and affected organisations activated continuity arrangements rather than simply waiting for the software provider to restore service.
There is another important legal distinction: vendor versus customer
The incident also demonstrates how Singapore’s data-protection rules divide responsibility between a technology provider and the organisation using that provider.
Avelogic says it notified the PDPC as a data intermediary.
Under Singapore’s PDPA framework, a data intermediary processes personal information on behalf of another organisation.
The organisation that controls why the information is being used — typically the employer in an HR system — retains separate responsibilities.
PDPC guidance says that when a data intermediary discovers a breach, it must notify the organisation it serves without undue delay.
The customer organisation must then assess whether the breach meets the threshold requiring notification to the PDPC and affected individuals.
Avelogic explicitly makes that same point in its current incident notice: its own filing does not automatically discharge each customer’s regulatory obligations.
When must affected people be told?
Under Singapore’s mandatory data-breach notification regime, organisations must notify the PDPC when a breach is likely to cause significant harm to individuals or is significant in scale.
Once an organisation determines that a breach is legally notifiable, it must notify the PDPC as soon as practicable and no later than three calendar days.
Where notification of affected individuals is required, they should also be informed as soon as practicable.
The fact that a vendor has made a notification therefore does not necessarily settle what each individual customer must do.
Their obligations depend on the nature and scale of the employee information affected.
PDPC is now investigating
CNA reported on Wednesday that a PDPC spokesperson confirmed the commission is aware of the matter and is investigating the data-breach notification filed over the incident.
That review could become important because the commission can examine whether appropriate data-protection and security obligations were met.
The PDPC has repeatedly stressed that organisations must make reasonable security arrangements to protect personal information from unauthorised access, collection, use or disclosure.
Its January 2026 advisory specifically highlighted failures to detect suspicious access and bulk downloading as common weaknesses discovered in previous breaches, recommending monitoring and data-loss-prevention controls.
It would be premature to conclude that those failings occurred in this case.
The cause and precise attack path have not been publicly established.
Third-party software creates a hidden chain of cyber risk
The MUIS-linked incident highlights a broader cybersecurity problem facing organisations everywhere.
A company may secure its own network carefully yet still rely on outside software for:
payroll,
employee records,
cloud storage,
email,
payments,
customer management,
and dozens of other functions.
Every additional provider becomes part of the organisation’s security chain.
If one software vendor is compromised, dozens or hundreds of customers can potentially be affected simultaneously.
Avelogic says more than 600 companies use SmartHRMS, although there is no indication that all of those customers were affected by this incident.
That scale is precisely why software-supply-chain incidents can spread far beyond a single compromised company.
Singapore has dealt with similar third-party breach questions before
PDPC enforcement history shows that organisations cannot automatically transfer all data-protection responsibility to outside vendors.
In previous ransomware cases, the commission has examined both the security measures of service providers and whether customer organisations exercised adequate oversight over companies processing data on their behalf.
PDPC guidance advises organisations to manage data intermediaries throughout their lifecycle, including security requirements, contracts, monitoring and exit arrangements.
That does not establish any breach of duty in the SmartHRMS incident.
But it explains why investigations may examine more than how the attackers initially gained access.
They can also look at how sensitive information was protected, how backups were structured, how quickly customers were informed and whether recovery arrangements were adequate.
The incident should not be confused with a breach of MUIS public services
Another important distinction has been lost in some social-media discussion.
MUIS says the incident does not affect public-facing or government services.
This was a compromise involving an HR management platform, not an announcement that MUIS’s entire digital infrastructure or public service systems had been taken offline.
Public access to religious services and government-facing functions remains unaffected, according to the council.
The operational disruption is centered on internal HR and payroll processes used by affected organisations.
Who was behind the ransomware attack?
At this stage, no publicly confirmed attacker has been identified.
Neither MUIS nor Avelogic has attributed the incident to a specific ransomware group, criminal gang or state-linked actor.
That matters because ransomware groups regularly make public claims about victims, and such claims are not automatically reliable.
Until investigators attribute the attack, any attempt to name a group would be speculation.
The police investigation remains ongoing.
Did Avelogic pay a ransom?
That is another unanswered question.
MUIS declined to elaborate while investigations continue.
Public incident notices do not disclose whether attackers demanded a specific amount, whether negotiations took place or whether any payment was made.
There is therefore no factual basis at present to claim that a ransom was paid.
The known fact is narrower: media reporting identifies the incident as ransomware, and Avelogic has been working to recover and rebuild the affected environment.
Employees should be alert for targeted phishing
Avelogic is specifically warning customers and employees to remain vigilant for suspicious communications that reference the incident.
It advises people to verify unexpected messages through official support channels rather than automatically trusting links or instructions.
That is particularly relevant after an HR-related cyberattack.
Even incomplete information about a person’s employer, job, salary system or contact details can make a phishing message sound far more credible.
A scammer might impersonate:
an HR officer,
a payroll administrator,
a bank,
the software provider,
or someone claiming an employee must “re-register” an account.
PDPC guidance similarly recommends independently verifying breach-related messages and avoiding immediate disclosure of personal or banking information in response to unsolicited requests.
The biggest unresolved number is how many people were affected
MUIS has not said.
Avelogic has not publicly identified the affected SmartHRMS customers.
And neither has disclosed a total number of employee records involved.
The Straits Times and Zaobao have reported that mosques and madrasahs were among the affected organisations, but the full scope remains under investigation.
That number will matter.
A cyberattack affecting dozens of employees creates one scale of privacy risk.
One involving thousands creates another.
It also affects whether notification requirements under Singapore law are triggered by the scale of the incident.
So what do we actually know?
The confirmed picture is narrower than some headlines may suggest.
A human-resource and payroll platform operated by Avelogic and used by organisations associated with MUIS suffered a cybersecurity incident involving ransomware.
The incident disrupted payroll and HR access.
Police and the PDPC are investigating.
MUIS has activated continuity measures.
Avelogic says it recovered the latest dataset and is rebuilding the service in an isolated environment.
And its independent forensic investigation says it has found no evidence of bulk data exfiltration in available network telemetry from the confirmed attack period.
What remains unknown is equally important.
How many employees were affected?
Which exact personal-data fields were exposed to attackers?
Did any smaller amount of information leave the system?
How did the attackers get in?
And will investigators identify a specific ransomware group?
Until those questions are answered, this should not be described either as a catastrophic confirmed data theft — or as an incident in which nothing sensitive was compromised.
The bigger lesson is hidden inside the payroll system
The attack is a reminder that some of the most valuable cyber targets are not flashy government websites or banking apps.
They are ordinary administrative systems that quietly sit behind organisations and store enormous amounts of personal information.
A payroll platform knows where someone works.
How much they earn.
Potentially where their salary is deposited.
Their leave history.
Their contact information.
And, depending on configuration, far more.
That makes HR software attractive to attackers even when the public has never heard of the product.
MUIS says public services remain unaffected.
Avelogic says bulk data theft has not been found.
And the system is being rebuilt.
But until the forensic and regulatory investigations are complete, the most important question remains unanswered: not whether hackers got into SmartHRMS — but exactly what they were able to see once they were inside.

Leave a Reply