The cyberattack affected an HR and payroll system supplied by Avelogic, not the delivery of MUIS’s religious or public-facing services. MUIS put alternative payroll arrangements in place for affected employees while Avelogic investigated and worked toward restoring SmartHRMS.
3
16
Who was affected, and did employees get paid?
MUIS said the affected community-sector users included 48 mosques, four madrasahs, the Islamic Learning Hub and Management Office (ILHAM), and the Mosque-Madrasah-Wakaf Shared Services (MMWSS). Avelogic’s system also served clients in other sectors. MUIS said the alternative arrangements would ensure affected mosque and madrasah employees received their salaries on time, with no disruption to religious or public-facing services.
3
Was employee information stolen?
That has not been established. Reporting identified employee names, contact details, salaries and bank-account numbers as information that might have been exposed; it did not confirm that those details were stolen. The available reporting also did not specify how many people were affected or precisely what information, if any, was compromised.
6
17
Avelogic said an independent forensic investigation found no evidence of bulk data exfiltration in the available Amazon Web Services network telemetry covering confirmed attacker activity from August 30 to 31. It also said core sensitive fields in SmartHRMS were protected by application-level encryption. Those findings limit what can be concluded from the evidence examined; they do not prove that no information was accessed or taken.
7
What was encrypted—and has SmartHRMS been restored?
Avelogic’s incident notice said the ransomware encrypted its databases and attached backups, disrupting access to the system. That is different from the application-level encryption intended to protect sensitive data fields. MUIS subsequently said Avelogic had recovered the affected data. Data recovery, however, is not the same as confirmation that customers had regained access to a fully restored system.
20
7
3
Earlier reporting described September 18 as a restoration target, but the supplied evidence does not confirm that SmartHRMS resumed service on that date. MUIS said investigations and security checks were ongoing.
10
16
What is the status of the investigations?
MUIS said a police report had been made, no ransom was paid, and Avelogic was continuing to investigate the incident and its wider impact. Avelogic’s incident notice also listed a filing with Singapore’s Personal Data Protection Commission (PDPC). The supplied evidence does not establish the outcome of the police investigation or the status or findings of any separate PDPC investigation.
3
20