← 返回新闻首页
新加坡本地

MUIS says salaries unaffected after cyberattack hits 48 mosques, Islamic institutions

Employees at 48 mosques and several Islamic institutions will continue to receive their salaries on time despite a cyberattack on HR software vendor Avelogic, with the Islamic Religious Council of Singapore (MUIS) saying alternative payroll arrangements are already in place.MUIS said on Thursday (Sept 17) that investigations have so far found "no evidence that a large amount of data was...

AsiaOne Singapore查看原文 ↗
MUIS says salaries unaffected after cyberattack hits 48 mosques, Islamic institutions
MUIS says salaries unaffected after cyberattack hits 48 mosques, Islamic institutions

Employees at 48 mosques and several Islamic institutions will continue to receive their salaries on time despite a cyberattack on HR software vendor Avelogic, with the Islamic Religious Council of Singapore (MUIS) saying alternative payroll arrangements are already in place.

MUIS said on Thursday (Sept 17) that investigations have so far found "no evidence that a large amount of data was taken" from the affected human resource management system (HRMS).

The HRMS operated by Singapore-based software vendor Avelogic serves MUIS and a number of Muslim community institutions.

Announcing preliminary findings from ongoing investigations, MUIS said that data stored in the HRMS was encrypted, providing an additional layer of protection.

However, the system will not resume operations just yet, despite Avelogic saying earlier this week that it had successfully recovered the last updated data set and was aiming to bring a new system online by Friday.

"The system will only resume operations after the relevant safeguards and checks have been completed," MUIS said.

Meanwhile, to mitigate any potential payroll impact on 48 mosques, four madrasahs, the Islamic Learning Hub and Management Office (ILHAM), and Mosque-Madrasah-Wakaf Shared Services (MMWSS), MUIS said it has put in place alternative payroll arrangements.

"MUIS is concerned about the impact on these organisations and their employees. MUIS is working with the affected institutions to ensure that employees will continue to receive their salaries on time."

It also confirmed that there has been no disruption to religious or public-facing services.

A police report was lodged by Avelogic on Aug 31 and no ransom was paid, with the vendor continuing its investigations into the incident and its wider impact, MUIS said.

The incident has affected Avelogic clients across different sectors.

Avelogic published a cybersecurity incident notice on its website concerning its SmartHRMS system.

The company said core sensitive data fields within the system remained protected through application-layer encryption.

A police report was filed on Aug 31, and the Personal Data Protection Commission (PDPC) was notified in its capacity as a data intermediary.

Responding to media queries, the PDPC said it was aware of the incident and had commenced investigations into the data breach notification.

In an update on Monday, the company said an independent forensic investigation had found no evidence of bulk data exfiltration, based on available Amazon Web Services network telemetry covering confirmed threat actor activity from Aug 30 to Aug 31.

It has since commissioned cybersecurity firm Blackpanda to conduct an independent forensic investigation.

手机左右滑动,电脑按 ← → 键,也能切换新闻