MUIS says salaries unaffected after cyberattack hits 48 mosques, Islamic institutions新加坡伊斯兰宗教理事会(MUIS)表示,网络攻击袭击48座清真寺和伊斯兰机构后,员工薪资未受影响。
Employees at 48 mosques and several Islamic institutions will continue to receive their salaries on time despite a cyberattack on HR software vendor Avelogic, with the Islamic Religious Council of Singapore (MUIS) saying alternative payroll arrangements are already in place.MUIS said on Thursday (Sept 17) that investigations have so far found "no evidence that a large amount of data was...

Employees at 48 mosques and several Islamic institutions will continue to receive their salaries on time despite a cyberattack on HR software vendor Avelogic, with the Islamic Religious Council of Singapore (MUIS) saying alternative payroll arrangements are already in place.
MUIS said on Thursday (Sept 17) that investigations have so far found "no evidence that a large amount of data was taken" from the affected human resource management system (HRMS).
The HRMS operated by Singapore-based software vendor Avelogic serves MUIS and a number of Muslim community institutions.
Announcing preliminary findings from ongoing investigations, MUIS said that data stored in the HRMS was encrypted, providing an additional layer of protection.
However, the system will not resume operations just yet, despite Avelogic saying earlier this week that it had successfully recovered the last updated data set and was aiming to bring a new system online by Friday.
"The system will only resume operations after the relevant safeguards and checks have been completed," MUIS said.
Meanwhile, to mitigate any potential payroll impact on 48 mosques, four madrasahs, the Islamic Learning Hub and Management Office (ILHAM), and Mosque-Madrasah-Wakaf Shared Services (MMWSS), MUIS said it has put in place alternative payroll arrangements.
"MUIS is concerned about the impact on these organisations and their employees. MUIS is working with the affected institutions to ensure that employees will continue to receive their salaries on time."
It also confirmed that there has been no disruption to religious or public-facing services.
A police report was lodged by Avelogic on Aug 31 and no ransom was paid, with the vendor continuing its investigations into the incident and its wider impact, MUIS said.
The incident has affected Avelogic clients across different sectors.
Avelogic published a cybersecurity incident notice on its website concerning its SmartHRMS system.
The company said core sensitive data fields within the system remained protected through application-layer encryption.
A police report was filed on Aug 31, and the Personal Data Protection Commission (PDPC) was notified in its capacity as a data intermediary.
Responding to media queries, the PDPC said it was aware of the incident and had commenced investigations into the data breach notification.
In an update on Monday, the company said an independent forensic investigation had found no evidence of bulk data exfiltration, based on available Amazon Web Services network telemetry covering confirmed threat actor activity from Aug 30 to Aug 31.
It has since commissioned cybersecurity firm Blackpanda to conduct an independent forensic investigation.
尽管人力资源软件供应商 Avelogic 遭到网络攻击,但新加坡伊斯兰宗教理事会 (MUIS) 表示,48 座清真寺和几家伊斯兰机构的员工仍将按时领取工资,替代工资安排已经到位。
新加坡伊斯兰宗教理事会(MUIS)周四(9月17日)表示,调查目前尚未发现“大量数据被盗取”的证据。
由新加坡软件供应商 Avelogic 运营的人力资源管理系统为新加坡伊斯兰宗教理事会 (MUIS) 和许多穆斯林社区机构提供服务。
新加坡伊斯兰宗教理事会(MUIS)公布了正在进行的调查的初步结果,称存储在人力资源管理系统(HRMS)中的数据已加密,提供了额外的保护层。
然而,尽管 Avelogic 本周早些时候表示已成功恢复了最后更新的数据集,并计划在周五之前将新系统上线,但该系统目前还不会恢复运行。
“只有在完成相关的安全保障和检查后,该系统才会恢复运行,”新加坡伊斯兰宗教理事会(MUIS)表示。
与此同时,为了减轻对 48 座清真寺、4 所伊斯兰学校、伊斯兰学习中心和管理办公室 (ILHAM) 以及清真寺-伊斯兰学校-瓦卡夫共享服务 (MMWSS) 可能造成的工资影响,MUIS 表示已制定替代工资安排。
“新加坡伊斯兰宗教理事会(MUIS)非常关注这些机构及其员工受到的影响。MUIS正与受影响的机构合作,确保员工能够继续按时领取工资。”
声明还证实,宗教活动或面向公众的服务没有受到影响。
新加坡伊斯兰宗教理事会(MUIS)表示,Avelogic 于 8 月 31 日向警方报案,但并未支付赎金,该供应商仍在继续调查这起事件及其更广泛的影响。
该事件对Avelogic在各个行业的客户都造成了影响。
Avelogic 在其网站上发布了有关其 SmartHRMS 系统的网络安全事件通知。
该公司表示,系统内的核心敏感数据字段通过应用层加密得到保护。
8月31日,警方立案调查,个人数据保护委员会(PDPC)作为数据中介机构也接到了通知。
针对媒体的询问,个人数据保护委员会表示,他们已经知晓此事,并已开始对数据泄露事件展开调查。
该公司周一发布最新消息称,一项独立的取证调查发现,根据亚马逊网络服务 (AWS) 提供的 8 月 30 日至 8 月 31 日期间已确认的威胁行为者活动网络遥测数据,没有发现大规模数据泄露的证据。
此后,该公司委托网络安全公司 Blackpanda 进行独立取证调查。