MUIS says human resource management system hit by cybersecurity incident
MUIS said the incident does not affect the delivery of public-facing or government services.
The Islamic Religious Council of Singapore (MUIS) has experienced a cybersecurity incident involving its human resource management system, operated by Singapore-based software vendor Avelogic. MUIS stated that the incident does not impact public-facing or government services. They are collaborating with Avelogic and relevant authorities to determine the appropriate next steps.
Business continuity measures have been put in place to support crucial HR and payroll operations. Affected employees receive guidance and support during the incident. MUIS has declined to provide additional details, citing ongoing investigations, and has not disclosed the number of people impacted or the compromised information.
The Singapore Police Force confirmed the filing of a police report and stated that investigations are ongoing. Avelogic published a cybersecurity incident notice on its website, asserting that an independent forensic investigation found no evidence of bulk data exfiltration. They emphasized that core sensitive data fields in their SmartHRMS system remained secure due to application-layer encryption.
The company filed a police report on August 31 and notified the Personal Data Protection Commission as a data intermediary. Avelogic engaged cybersecurity firm Black Panda to conduct an independent forensic investigation, which successfully recovered the last updated data set. The company aims to restore other system components progressively.
Written by urgent.news from CNA - Singapore's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- MUIS says human resource management system hit by cybersecurity incident channelnewsasia.com