A ransomware attack has shut down the payroll and HR system used by Singapore's Islamic Religious Council, exposing staff data but leaving public services running. Authorities and provider Avelogic are investigating and working to restore security.
Payroll for dozens of Singapore's mosques and madrasahs came to a standstill after a ransomware attack hit the SmartHRMS system. Accounting staff were locked out and had to process salaries manually. The breach targeted the platform supplied by Avelogic and used by the Islamic Religious Council of Singapore (MUIS), exposing employee details such as names, contact information, salaries, and bank account numbers. SmartHRMS, hosted on AWS, automates payroll, leave, claims, and attendance for 69 mosques, three madrasahs, and two wakafs under the Mosque-Madrasah-Wakaf Shared Services (MMWSS) committee.
Despite the disruption, MUIS says that public-facing and government services are still running. Business continuity plans were put in place right away, allowing essential HR and payroll tasks to continue, though with manual workarounds. Employees affected by the outage are being supported as the council tries to manage the fallout. The incident highlights the need for strong cybersecurity for SaaS platforms that handle sensitive data, especially as regulations tighten in Europe and Asia.
Core system targeted
MUIS confirmed the attack on 15 September. The system handles payroll for much of Singapore's religious sector workforce. According to Avelogic, suspicious activity was first noticed between 30 and 31 August. Black Panda, a forensic firm brought in on 3 September, found no evidence of large-scale data theft after reviewing AWS network logs. Avelogic said that sensitive fields were protected by application-layer encryption, a practice now required by European data protection authorities like the Garante Privacy.
Still, the breach forced a scramble to recover the latest data and rebuild the platform. Full restoration was targeted for 18 September, with other components to follow. Avelogic filed a police report on 31 August and notified Singapore's Personal Data Protection Commission, following standard procedures for breach notification and forensic response.
Ongoing investigation and official response
MUIS, Avelogic, and the authorities are working together, but few details have been released while the investigation continues. Avelogic has notified the Personal Data Protection Commission (PDPC) and filed a police report. The company has not named MUIS as the affected client, but the council's statement makes the target clear. SmartHRMS uses cloud-native architecture and encrypted storage, which matches current best practices, but the incident shows that ransomware remains a threat even for well-defended systems.
Ransomware attacks usually involve hackers encrypting or stealing data, then demanding payment to prevent leaks or restore access. In this case, the attackers' demands have not been made public, and MUIS has declined to comment further while the investigation is ongoing. The breach also raises questions about compliance with European and Italian cybersecurity rules, such as those enforced by ACN and AGCOM, which require prompt breach notification and technical safeguards for critical digital services.
Impact and context in the digital landscape
While the immediate impact has been contained, the breach shows how vulnerable critical HR systems can be in the public and religious sectors. The SmartHRMS outage forced a return to manual payroll, a reminder that digital systems can quickly become a liability when security fails. This incident is similar to other ransomware campaigns, like those described in our earlier report on Mantax Otax, where attackers combine data theft with extortion.
Singapore's response-quick notification of authorities, forensic analysis, and open communication with affected staff-sets a standard for crisis management, but the risk remains. As more essential services move to cloud platforms, the consequences of cybersecurity failures grow. The fact that core data was encrypted and no mass data theft was found is reassuring, but even well-protected systems can be breached. Until organizations treat cybersecurity as a basic requirement, ransomware will remain a threat, regardless of the institution.