2026 Avelogic SmartHRMS — Aug 30–31 ransomware; MUIS mosque/madrasah payroll systems affected
Data compromised
Employee/payroll/leave records for customer organizations (including MUIS-linked mosques and madrasahs) potentially at risk — names, contacts, salaries, bank numbers cited in press; Avelogic forensic update said no evidence of bulk exfiltration on available AWS telemetry; core sensitive fields claimed application-layer encrypted
Technical writeup
Verified Avelogic / MUIS disclosures — September 2026. Avelogic detected threat-actor activity on SmartHRMS Aug 30–31; databases including backups encrypted; police report Aug 31; PDPC notified as data intermediary; Black Panda forensics engaged. Sep 14 update: no evidence of bulk data exfiltration on available AWS telemetry; last dataset recovered; restore targeted ~Sep 18. MUIS confirmed the HR/payroll vendor incident affecting mosques/madrasahs shared services; public/government services unaffected; continuity for payroll. Staff census not published. recordsAffected 0; companyConfirmed true.
Root cause
Ransomware / threat-actor activity detected Aug 30–31, 2026 on SmartHRMS; databases and backups encrypted
References
- https://www.straitstimes.com/singapore/courts-crime/payroll-system-of-mosques-madrasahs-hit-by-ransomware-staff-details-potentially-compromised
- https://www.channelnewsasia.com/singapore/muis-human-resource-payroll-management-system-cyberattack-6386546
- https://databreaches.net/2026/09/15/payroll-system-of-mosques-madrasahs-hit-by-ransomware-staff-details-potentially-compromised/