Key Takeaways

  • Avelogic detected malicious activity affecting SmartHRMS on Aug 30 and 31, disrupting payroll access for mosques and madrasahs overseen by MUIS.
  • Staff names, contact details, salaries and bank account numbers may have been exposed, although Avelogic found no evidence of bulk data theft.
  • The incident highlights the need for isolated backups, stronger payroll-access controls and tested manual recovery procedures.

A ransomware incident affecting Avelogic's SmartHRMS platform has disrupted payroll operations across mosques and madrasahs overseen by the Islamic Religious Council of Singapore (MUIS). Accounting personnel temporarily lost access to the human resources system and had to process salaries manually, according to an affected individual. MUIS said public-facing and government services were not affected, while continuity arrangements were activated for essential HR and payroll work.

Avelogic detected threat-actor activity on Aug 30 and 31. In a Sept 7 incident notice, Avelogic said attackers had encrypted its databases, including backup copies, leaving no available recovery point at that stage. Unexplained outbound data transfers also meant Avelogic could not initially rule out data theft. The combination of production encryption and inaccessible backups is particularly serious because it can remove the fastest path to operational recovery.

The picture improved somewhat by Sept 14. Avelogic said its investigation had found no evidence that data was stolen in bulk and that the latest updated data set had been recovered. Avelogic was targeting Sept 18 for restoration of its systems. Even so, absence of evidence for bulk exfiltration does not establish that no individual files, credentials or records were accessed. The forensic investigation will be central to determining the incident's scope.

Potentially affected information is believed to include employee names, contact details, salaries and bank account numbers. MUIS has not disclosed how many mosques and madrasahs were affected, what information was compromised, whether any ransom was paid or how recovery was achieved. MUIS cited continuing investigations. The Mosque-Madrasah-Wakaf Shared Services, a committee under MUIS, provides SmartHRMS to generate payslips and handles accounts for 69 of Singapore's 72 mosques and three madrasahs.

Payroll data has value well beyond the immediate ransom demand. Salary details, contact information and bank records can support targeted phishing, impersonation and payment-diversion attempts. Microsoft Threat Intelligence documented "payroll pirate" attacks in 2025 in which compromised university employee accounts were used to alter direct-deposit information in HR services such as Workday. Follow-on fraud after a ransomware event depends heavily on exactly what the attackers accessed and whether usable credentials were captured.

Avelogic has filed a police report, notified the Personal Data Protection Commission (PDPC) and commissioned an independent forensic investigation by a cybersecurity specialist. Singapore police confirmed that an investigation is under way, while the PDPC said it was investigating Avelogic's breach notification. For MUIS and affected employers, the response involves reviewing payroll changes, warning personnel about convincing phishing messages and applying additional verification to requests involving bank details.

Recovery design requires precise architecture. NIST IR 8374 Rev. 1, published in 2026, emphasizes containment, recovery planning and limiting the blast radius of ransomware across critical systems. Applied to payroll, that approach includes segmented infrastructure, tightly restricted administrative access, multifactor authentication, detailed logging and backups that cannot be modified through the same credentials used to manage production systems.

Technology controls are only part of the response. Organizations must maintain rehearsed procedures for calculating salaries, approving payments and communicating with personnel when HR applications go offline. CBC News reported in December 2025 on the conclusion of an investigation into a ransomware attack involving the Pembina Trails school division, demonstrating that education and administrative environments remain recurring targets.

The immediate benchmark for Avelogic will be whether SmartHRMS returns safely by Sept 18 without reintroducing compromised systems or accounts. Longer term, MUIS, Avelogic and affected institutions face the difficult task of establishing exactly what attackers reached, supporting employees whose information may have been exposed, and rebuilding confidence in a shared payroll service connecting dozens of institutions.