← 返回新闻首页
新加坡权威

MUIS says human resource management system hit by cybersecurity incident

MUIS said the incident does not affect the delivery of public-facing or government services.

CNA SingaporeEmil Chan查看原文 ↗
新加坡伊斯兰宗教理事会(MUIS)称,人力资源管理系统遭受网络安全事件攻击

MUIS said the incident does not affect the delivery of public-facing or government services.

Exterior of the Islamic Religious Council of Singapore (MUIS) building. (Photo: Majlis Ugama Islam Singapura)

This audio is generated by an AI tool.

SINGAPORE: The Islamic Religious Council of Singapore (MUIS) has been hit by a cybersecurity incident involving a human resource management system operated by Singapore-based software vendor Avelogic.

It is working closely with the affected organisations, Avelogic and the relevant authorities on the necessary next steps, said MUIS in response to CNA queries on Tuesday (Sep 15).

The incident does not affect the delivery of public-facing or government services, it added.

“Business continuity arrangements have been implemented to support essential HR and payroll functions, and affected employees are being provided with the necessary guidance and support,” Muis said.

CNA Games Guess Word Crack the word, one row at a time Buzzword Create words using the given letters Mini Sudoku Tiny puzzle, mighty brain teaser Mini Crossword Small grid, big challenge Word Search Spot as many words as you can Show More Show Less MUIS declined to give further information, citing ongoing investigations. It did not specify how many people were affected or what information may have been compromised. The Singapore Police Force confirmed with CNA that a report was lodged and that investigations are ongoing. Separately, Avelogic has published a cybersecurity incident notice on its website concerning its SmartHRMS system. In an update dated Monday, the company said an independent forensic investigation had found no evidence of bulk data exfiltration, based on available Amazon Web Services network telemetry covering confirmed threat actor activity from Aug 30 to Aug 31. Avelogic did not identify the customers affected in the notice. On its website, the company described the SmartHRMS system as "Singapore's CPF-compliant payroll and HR management system for SMEs - automating payroll, leave, claims, employee self-service and attendance in one integrated cloud platform". The company said in the cybersecurity incident notice that core sensitive data fields within SmartHRMS remained protected by application-layer encryption. Avelogic filed a police report on Aug 31 and notified the Personal Data Protection Commission in its capacity as a data intermediary. It commissioned cybersecurity firm Black Panda on Sep 3 to conduct an independent forensic investigation. The firm added that it successfully recovered the last updated data set, and was aiming to get its new system by Friday. “Other components of the system will be brought back online progressively thereafter”, said Avelogic.

MUIS declined to give further information, citing ongoing investigations.

It did not specify how many people were affected or what information may have been compromised.

The Singapore Police Force confirmed with CNA that a report was lodged and that investigations are ongoing.

Separately, Avelogic has published a cybersecurity incident notice on its website concerning its SmartHRMS system.

In an update dated Monday, the company said an independent forensic investigation had found no evidence of bulk data exfiltration, based on available Amazon Web Services network telemetry covering confirmed threat actor activity from Aug 30 to Aug 31.

Avelogic did not identify the customers affected in the notice.

On its website, the company described the SmartHRMS system as "Singapore's CPF-compliant payroll and HR management system for SMEs - automating payroll, leave, claims, employee self-service and attendance in one integrated cloud platform".

The company said in the cybersecurity incident notice that core sensitive data fields within SmartHRMS remained protected by application-layer encryption.

Avelogic filed a police report on Aug 31 and notified the Personal Data Protection Commission in its capacity as a data intermediary.

It commissioned cybersecurity firm Black Panda on Sep 3 to conduct an independent forensic investigation.

The firm added that it successfully recovered the last updated data set, and was aiming to get its new system by Friday.

“Other components of the system will be brought back online progressively thereafter”, said Avelogic.

Get our pick of top stories and thought-provoking articles in your inbox

Stay updated with notifications for breaking news and our best stories

Join our channel for the top reads for the day on your preferred chat app

手机左右滑动,电脑按 ← → 键,也能切换新闻