Payroll system of mosques, madrasahs hit by ransomware; staff details potentially compromised清真寺和伊斯兰学校的工资系统遭勒索软件攻击;员工信息可能泄露
The system contained details of staff at dozens of mosques, including their salaries and bank account numbers. Read more at straitstimes.com.
When contacted by ST, MUIS confirmed the incident involving a HR management system operated by Avelogic.
PHOTO: LIANHE ZAOBAO
Published Sep 15, 2026, 08:43 PM
Updated Sep 15, 2026, 08:43 PM
The payroll system SmartHRMS, used by mosques and madrasahs under MUIS in Singapore, was hit by a ransomware attack in August, compromising sensitive staff salary and bank details.
Hackers encrypted the system and backups, disrupting payroll processing, but investigation found no bulk data theft; recovery efforts aim to restore service by Sept 18.
Avelogic reported the incident to police and PDPC, and has hired cybersecurity experts for forensic analysis.
SINGAPORE - The payroll system of mosques and madrasahs overseen by the Islamic Religious Council of Singapore (MUIS) has been hacked and held for ransom, The Straits Times has learnt.
The SmartHRMS human resource (HR) system is supplied by Singapore-based software vendor Avelogic.
The latest cyber security incident notice on Avelogic’s website, which was last updated on Sept 14, stated that threat actor activity was first detected on Aug 30 and 31. Avelogic did not name the customers affected.
“We are working closely with the affected organisations, Avelogic and the relevant authorities on the necessary follow-up actions,” said MUIS.
“This incident does not affect the delivery of public-facing or Government services. Business continuity arrangements have been implemented to support essential HR and payroll functions, and affected employees are being provided with the necessary guidance and support,” it said.
MUIS declined to reveal how many mosques and madrasahs were affected, and what sensitive information - including the assets it manages and staff details - was compromised. It also declined to reveal if it has paid the ransom, and whether data has been recovered, citing ongoing investigations.
The compromised system is believed to have contained sensitive information of staff at dozens of mosques and madrasahs, including their names, contact details, salaries and bank account numbers.
An affected individual who spoke to ST on condition of anonymity said accounting staff could not log in to the system after the attack, forcing them to scramble to process salaries manually.
The SmartHRMS system was supplied to mosques and madrasahs by the Mosque-Madrasah-Wakaf Shared Services, a committee under MUIS.
There are 72 mosques in Singapore.
In a ransomware attack, hackers either steal the data and threaten to release it publicly or lock the compromised data by encrypting it, disrupting operations.
Victims are asked to pay a ransom either to prevent their sensitive data from being leaked publicly or to have their databases unlocked so they can continue operating.
A Sept 7 notice on Avelogic’s website about the incident said the hackers had encrypted its databases, including back-up copies , leaving no recovery point. This initial notice also said it could not rule out data theft as there were unexplained outbound transfers.
An updated notice on Sept 14, however, said that its investigation found no evidence that data was stolen in bulk. The firm added that it was able to recover the last updated data set. It was aiming to have its systems running again by Sept 18.
Avelogic has filed a police report and notified the Personal Data Protection Commission (PDPC), and commissioned an independent forensic investigation by a cybersecurity firm.
The police confirmed a report was lodged and investigations are ongoing.
A PDPC spokesperson said it was aware and investigating the data breach notification filed by Avelogic.
David Sun is The Straits Times’ crime correspondent. He has a background in criminology and is a licensed private investigator.
ST联系MUIS后,MUIS证实了这起事件涉及Avelogic运营的人力资源管理系统。
图片来源:联合早报
发布于 2026 年 9 月 15 日晚上 8:43
更新于2026年9月15日晚上8:43
新加坡伊斯兰宗教理事会 (MUIS) 下属清真寺和伊斯兰学校使用的薪资系统 SmartHRMS 在 8 月份遭受勒索软件攻击,导致员工的敏感薪资和银行信息泄露。
黑客对系统和备份进行了加密,导致工资处理中断,但调查发现没有大量数据被盗;恢复工作的目标是在 9 月 18 日之前恢复服务。
Avelogic 已向警方和 PDPC 报告了这起事件,并聘请了网络安全专家进行取证分析。
新加坡——据《海峡时报》报道,新加坡伊斯兰宗教理事会(MUIS)监管的清真寺和伊斯兰学校的工资系统遭到黑客攻击并被勒索赎金。
SmartHRMS 人力资源 (HR) 系统由总部位于新加坡的软件供应商 Avelogic 提供。
Avelogic 网站上最新的网络安全事件通知(上次更新时间为 9 月 14 日)称,威胁行为者的活动最早于 8 月 30 日和 31 日被检测到。Avelogic 没有透露受影响的客户姓名。
“我们正在与受影响的组织、Avelogic公司和相关部门密切合作,采取必要的后续行动,”新加坡伊斯兰宗教理事会(MUIS)表示。
声明称:“此次事件不会影响面向公众或政府服务的提供。我们已实施业务连续性安排,以支持必要的人力资源和薪资职能,并正在为受影响的员工提供必要的指导和支持。”
新加坡伊斯兰宗教理事会(MUIS)拒绝透露有多少清真寺和伊斯兰学校受到影响,以及哪些敏感信息(包括其管理的资产和员工信息)遭到泄露。该理事会还以调查仍在进行为由,拒绝透露是否已支付赎金以及数据是否已恢复。
据信,被入侵的系统包含数十座清真寺和伊斯兰学校工作人员的敏感信息,包括他们的姓名、联系方式、工资和银行账号。
一位不愿透露姓名的受影响人士告诉《海峡时报》,攻击发生后,会计人员无法登录系统,迫使他们匆忙手动处理工资。
SmartHRMS 系统由穆斯林伊斯兰理事会 (MUIS) 下属的清真寺-伊斯兰学校-瓦卡夫共享服务委员会提供给清真寺和伊斯兰学校。
新加坡共有72座清真寺。
在勒索软件攻击中,黑客要么窃取数据并威胁公开泄露,要么通过加密锁定被入侵的数据,从而扰乱运营。
受害者被要求支付赎金,以防止其敏感数据被公开泄露,或者解锁其数据库以便继续运营。
Avelogic公司9月7日在其网站上发布公告,称黑客已加密其数据库(包括备份副本),导致数据无法恢复。该公告还指出,由于存在无法解释的出站数据传输,因此不能排除数据被盗的可能性。
然而,9月14日发布的最新公告称,调查未发现数据被批量窃取的证据。该公司补充说,已成功恢复了最后更新的数据集。其目标是在9月18日前恢复系统运行。
Avelogic 已向警方报案,并通知了个人数据保护委员会 (PDPC),同时委托一家网络安全公司进行独立的取证调查。
警方证实已接到报案,调查正在进行中。
菲律宾个人数据保护委员会(PDPC)发言人表示,他们已经知悉并正在调查Avelogic提交的数据泄露通知。
大卫·孙是《海峡时报》的犯罪记者。他拥有犯罪学背景,并且是一名持证私人侦探。