The Islamic Religious Council of Singapore (MUIS) confirmed that the payroll system used by mosques and madrasahs under its oversight was targeted in a ransomware attack, potentially compromising staff information. The affected system, SmartHRMS, is provided by Avelogic, a local software vendor.

According to Avelogic's cybersecurity incident updates, the malicious activity was first detected on August 30 and 31. MUIS acknowledged the breach but did not disclose how many institutions or individuals were affected, nor the extent of the data compromised. The council stated that the incident did not impact public-facing or government services and that business continuity measures have been implemented to maintain essential human resources and payroll operations.

The compromised system is believed to have contained sensitive data on employees across dozens of mosques and madrasahs, including personal details such as names, contact information, salaries, and bank account numbers. An individual familiar with the incident, speaking on condition of anonymity, said that accounting staff were unable to access the HR system following the attack, necessitating manual salary processing.

The council did not comment on whether a ransom had been paid or whether data had been recovered, citing ongoing investigations. Avelogic’s initial public statement on September 7 revealed that hackers had encrypted both their primary and backup databases, effectively eliminating recovery points. The company also reported suspicious outbound data transfers but could not confirm data theft at that time.

An update issued on September 14 indicated no evidence of bulk data exfiltration, and Avelogic announced it had successfully restored the most recent data set. The vendor aimed to resume normal system operations by September 18.

Avelogic has filed a police report and notified the Personal Data Protection Commission (PDPC). The company has also appointed an independent cybersecurity firm to conduct a forensic investigation. Police confirmed that they are investigating the case, and a PDPC spokesperson said the commission is reviewing the data breach notification submitted by Avelogic.