← Blog

Avelogic SmartHRMS Ransomware Hits MUIS Payroll

Share on X

August 30–31, 2026: Singapore payroll vendor Avelogic detected threat-actor activity on its SmartHRMS cloud HR platform. Databases — including backups — were encrypted. The Islamic Religious Council of Singapore (MUIS) later confirmed the Avelogic MUIS payroll incident hit mosque and madrasah shared-services systems. Canonical: avelogic-smarthrms2026. Primary reporting: The Straits Times, CNA.

Ransomware against a CPF-compliant payroll stack is not abstract. When the system that prints payslips locks up, accounting staff scramble to pay people by hand — and every staffer whose salary and bank details live in that database has to assume phishing season just started. That is the Avelogic SmartHRMS ransomware story as of mid-September 2026: vendor confirmation, MUIS confirmation, PDPC notified, forensics underway, and still no public headcount of whose records sat in the encrypted stores.

What happened in the Avelogic SmartHRMS ransomware incident

Avelogic’s cybersecurity incident notice — last updated September 14, 2026, and covered by CNA and The Straits Times — says threat-actor activity on SmartHRMS was first detected on August 30 and 31. The attackers encrypted production databases and backup copies. An earlier September 7 notice said that left the vendor with no recovery point and that unexplained outbound transfers meant data theft could not be ruled out.

By September 14 the tone shifted. Avelogic said an independent forensic investigation found no evidence of bulk data exfiltration on available Amazon Web Services network telemetry for the confirmed threat-actor window of August 30–31. The company said it recovered the last updated dataset and was targeting a restore around September 18, with other components coming back online progressively after that.

Avelogic filed a police report on August 31. The Singapore Police Force confirmed to media that a report was lodged and investigations continue. The vendor notified the Personal Data Protection Commission (PDPC) in its capacity as a data intermediary. A PDPC spokesperson told CNA the commission was aware and investigating the notification. On September 3, Avelogic commissioned cybersecurity firm Black Panda for independent forensics.

Avelogic’s public notice did not name customers. MUIS did that work for reporters. When The Straits Times and CNA asked, MUIS confirmed a cybersecurity incident involving the human-resource management system operated by Avelogic and said it was working with affected organisations, the vendor, and authorities.

Who uses SmartHRMS — and why MUIS matters

SmartHRMS is Avelogic’s Singapore-marketed, CPF-compliant payroll and HR platform for SMEs: payroll, leave, claims, employee self-service, and attendance in one cloud system. That product surface is exactly why a ransomware hit is so disruptive. Encrypt the HR database and you do not just lose a file share — you lose the operational path that generates payslips.

For the mosque and madrasah community, SmartHRMS was supplied through the Mosque-Madrasah-Wakaf Shared Services committee under MUIS. Straits Times reporting notes Singapore has 72 mosques, and that the committee handles accounts for 69 mosques and three madrasahs, including payroll systems used to generate payslips. MUIS declined to say how many sites were affected in this specific incident or what sensitive fields were compromised.

MUIS was clear on what this is not. The incident does not affect delivery of public-facing or government services. Business-continuity arrangements were put in place for essential HR and payroll functions, and affected employees were being given guidance. An anonymous accounting staffer told The Straits Times that colleagues could not log in after the attack and had to process salaries manually — the operational footprint of encryption, even before any debate about whether data left the cloud.

What data was potentially at risk

No official census of affected staff has been published. Treat any round number floating on social media as unverified.

Press coverage, citing the nature of a payroll HR system and anonymous sources, says the compromised environment is believed to have held sensitive staff information for people at dozens of mosques and madrasahs, including:

  • Names
  • Contact details
  • Salaries
  • Bank account numbers

MUIS declined to confirm that field list or whether ransom was paid. Avelogic’s September 14 update claimed that core sensitive data fields within SmartHRMS remained protected by application-layer encryption. That claim is material if true — it narrows what an attacker who only encrypted at rest might read in cleartext — but it is not the same as a PDPC finding that no personal data was accessible. Application-layer encryption protects the fields it covers; leave balances, organisational charts, and other non-“core” attributes may still be useful for social engineering even when salary or bank columns stay ciphertext.

The forensic sequence matters for how staff should think about risk. The September 7 notice could not rule out theft because of unexplained outbound transfers. The September 14 notice said available AWS telemetry for the confirmed actor window showed no evidence of bulk exfiltration, and that the last dataset had been recovered. “No evidence of bulk exfil on available telemetry” is a meaningful investigative finding. It is not a lifetime guarantee that nothing left the environment, that every log source was retained, or that every customer’s offline copy was untouched. Until PDPC or MUIS publishes a final determination, treat bulk theft as not evidenced so far — not as impossible.

How the Avelogic data breach unfolded on a timeline

Here is the sequence as attested in vendor notices and Singapore press:

  • August 30–31, 2026: Threat-actor activity detected on SmartHRMS; databases and backups encrypted.
  • August 31: Avelogic files a police report.
  • September 3: Black Panda engaged for independent forensics.
  • September 7 notice: Encryption of databases and backups with no recovery point; unexplained outbound transfers mean data theft cannot be ruled out.
  • September 14 update: No evidence of bulk exfiltration on available AWS telemetry for Aug 30–31; last updated dataset recovered; restore targeted around September 18.
  • September 15–16 press: MUIS confirms the Avelogic HR/payroll incident; PDPC says it is investigating the intermediary notification; police confirm an ongoing probe.

What has not been published: the initial access path (stolen VPN credential, exposed RDP, phishing of an admin, vulnerable edge device — unknown), the ransomware family name, whether a ransom note named a group, whether any payment was made, and how many employee records sat in the encrypted stores. Absence of those details is normal early in a Singapore vendor investigation; it is also why this write-up will not invent a root-cause narrative.

Who is at risk after the MUIS payroll cyberattack

Mosque and madrasah staff whose HR and payroll records lived in the shared SmartHRMS instance are the primary population. If you received guidance from MUIS or your mosque’s admin office, follow that channel first. Assume attackers — or opportunistic fraudsters reading the headlines — will try salary-related phishing even if forensics ultimately show no bulk dump.

Accounting and HR operators who scrambled through manual payroll are also in the blast radius for business-email compromise. Expect fake “updated bank details for September salary” messages, fake vendor invoices, and fake PDPC or police follow-ups asking for NRIC uploads.

Other Avelogic SmartHRMS customers outside the MUIS shared-services footprint should watch Avelogic’s incident page and their own admin mail. The vendor did not name every customer. If your organisation runs SmartHRMS, ask your account manager in writing whether your tenant was in the affected environment and what the September 14 forensic conclusions mean for your logs.

The general public and mosque worshippers are not the primary cohort described in coverage. MUIS said public-facing and government services were unaffected. That does not mean scammers will ignore MUIS branding — only that the confirmed incident perimeter is HR/payroll shared services, not every MUIS digital channel.

Industry context: payroll SaaS ransomware and Singapore intermediaries

Payroll platforms concentrate exactly the fields criminals monetise: identity anchors, salary bands, and bank numbers. Encrypting those systems creates dual pressure — operational ransom for decrypt keys, and secondary fraud against employees if any cleartext leaves the environment. Singapore’s PDPC framework treating vendors as data intermediaries is why Avelogic’s notification path matters as much as MUIS’s customer-side statement. The intermediary files; the organisation that employs the staff still owes its people practical guidance.

Similar patterns show up whenever a shared-services committee or outsourced payroll host is hit: one vendor outage fans out across dozens of small organisations that never ran their own HR stack. The Mosque-Madrasah-Wakaf Shared Services model is efficient until the single cloud payroll system becomes a single point of failure. Backups encrypted alongside production is the classic lesson every SaaS vendor relearns the hard way — immutable, offline, or cross-account backups are not optional for a CPF payroll database.

Compare this calmly to other 2026 vendor incidents catalogued on BreachHistory: third-party verification providers, HR platforms, and managed IT hosts keep appearing because attackers prefer one intrusion that reaches many employers. The Avelogic case is notable because MUIS confirmed customer impact quickly in press while the vendor’s forensic story moved from “cannot rule out theft” to “no bulk exfil on available AWS telemetry” within a week.

What Avelogic, MUIS, police, and PDPC said

Avelogic’s published narrative centres on detection, encryption of databases and backups, police and PDPC notification, Black Panda forensics, the AWS telemetry finding against bulk exfiltration, recovery of the last dataset, and a September 18 restore target. The vendor also asserted application-layer encryption on core sensitive fields.

MUIS confirmed the incident, stressed continuity for essential HR and payroll, said public-facing and government services were unaffected, and declined further detail pending investigations. Police confirmed a report and ongoing investigations. PDPC confirmed awareness and investigation of Avelogic’s data-breach notification.

None of those statements yet equals a final PDPC determination letter with a published records-affected figure. BreachHistory therefore catalogues the incident as company-confirmed with recordsAffected unpublished (0 in catalog numeric fields until a census appears). Staff should not read “0” as “nobody was in the database.”

What you should do if you may be affected

If you work at a mosque or madrasah that used the shared SmartHRMS payroll path — or if Avelogic or your employer told you your organisation was in scope — treat the next few months as elevated fraud risk:

  1. Use official channels only. Verify payslip or bank-detail changes through phone numbers you already have for your mosque admin office or MUIS guidance — not through links in unexpected SMS or WhatsApp messages.
  2. Watch salary and bank phishing. Messages claiming “September payroll failed — re-enter your bank account” are classic post-breach bait. Your bank will not ask you to paste full account numbers into a fresh form via a random link.
  3. Enable transaction alerts on the accounts that receive salary. Flag unexpected eGIRO changes or small test withdrawals immediately.
  4. Do not pay anyone claiming to be Avelogic, MUIS, PDPC, or SPF asking for a “recovery fee” or “decrypt fee” from individuals. Ransom demands, if any, are organisational. Individuals get scammed with fake authority fees.
  5. Rotate reused passwords if you ever logged into SmartHRMS employee self-service with a password you reuse elsewhere. Prefer a password manager and MFA where the product supports it.
  6. Keep paperwork. Save employer notices and screenshots of any suspicious payroll messages. If fraud occurs, you will need a timeline for the bank and police.
  7. Follow PDPC and employer updates rather than Telegram rumour channels for whether bulk exfiltration is later confirmed or ruled out more definitively.

What this Avelogic breach is not

It is not, on current evidence, a confirmed bulk dump of every mosque worker’s salary file onto a leak site. Avelogic’s September 14 forensic update specifically said available AWS telemetry for the actor window did not show bulk exfiltration. It is not an outage of MUIS public or government services. It is not a published headcount — anyone quoting “tens of thousands of NRICs stolen” without a primary notice is inventing.

It is a verified ransomware disruption of a payroll SaaS used in MUIS-linked shared services, with police and PDPC processes underway, and with staff personal data types that press believes were present in the system potentially at risk depending on what encryption and telemetry ultimately prove.

Operational impact: encrypted payroll and manual workarounds

Encryption of a live payroll database is a different crisis from a leaked marketing list. Payslips stop generating. Leave balances freeze in the UI. Claims workflows die. Accounting staff who told The Straits Times they could not log in were not describing a minor inconvenience — they were describing the moment a shared-services committee becomes a spreadsheet operation overnight.

Business-continuity language from MUIS — that essential HR and payroll functions continued under contingency arrangements — should be read as “people still got paid somehow,” not “SmartHRMS stayed fully available.” Manual payroll is slower, error-prone, and creates its own fraud surface: temporary bank-detail collection sheets, WhatsApp photo-of-payslip workflows, and rushed approvals that attackers love to spoof.

The backup failure mode is equally important. Avelogic’s September 7 notice said databases including backup copies were encrypted, leaving no recovery point. That is the textbook ransomware outcome when backups share credentials, network reachability, or identity with production. The September 14 recovery of a last updated dataset implies the forensics and restore team found a viable copy after the initial “no recovery point” assessment — good news for operations, and a reminder that early incident notices often describe the worst case visible on day one.

Reading the AWS telemetry finding carefully

Cloud forensics language is easy to over-read. “No evidence of bulk data exfiltration on available Amazon Web Services network telemetry covering confirmed threat actor activity from Aug 30 to Aug 31” packs several limits into one sentence.

Available telemetry means the VPC flow logs, firewall logs, or CloudTrail-adjacent network views Black Panda and Avelogic could still query — not every possible packet capture that might have existed if logging had been configured differently. Confirmed threat actor activity bounds the window to August 30–31; it does not automatically prove no earlier access. Bulk exfiltration leaves room for small, selective pulls that never look like a multi-gigabyte spike. None of those caveats accuse Avelogic of hiding a dump. They explain why staff should still watch for salary phishing while welcoming the updated finding.

Application-layer encryption on core sensitive fields is the other technical claim staff ask about. If salary and bank columns were ciphertext to the attacker’s session, cleartext exposure may be narrower than a raw SQL dump implies. If the attacker obtained application keys or operated through the application after authenticating as a privileged user, field encryption may not help. Public notices have not walked through key custody. Treat the claim as a mitigating control Avelogic asserts — not as a completed PDPC conclusion that no bank numbers were readable.

Fraud playbook against mosque and madrasah staff

Even without a confirmed bulk dump, headline-driven fraud only needs institution names and a payroll story. Expect fake CPF mismatch SMS, spoofed Shared Services “emergency payslip” PDFs, bank calls that already know your mosque’s name, and fake PDPC portals demanding NRIC uploads. Legitimate PDPC and police processes do not start with cold links. Use employer or MUIS guidance; when unsure, hang up and dial a number from an old payslip.

What other SmartHRMS customers should ask

If you run SmartHRMS and lack a direct notice, ask in writing whether your tenant was affected, which logs informed the no-bulk-exfil finding, whether application encryption keys were rotated, and whether employee self-service passwords should be forced to reset. Also inventory offline staff bank CSVs and admin MFA — a clean cloud restore does not recall a spreadsheet emailed last year.

Canonical record and sources

BreachHistory’s living catalog entry for this incident is https://breachhistory.com/avelogic/avelogic-smarthrms2026. For primary reporting, read The Straits Times coverage, CNA’s MUIS confirmation piece, and the DataBreaches.net summary. When Avelogic, MUIS, or PDPC publish a final census or field list, that catalog row — and this narrative’s risk framing — should be updated.

Until then, the practical posture for affected staff is simple: trust official payroll channels, treat salary phishing as likely, and remember that “no bulk exfil on available telemetry” is an investigative status, not a reason to ignore a fake payslip email that looks almost right.