Payroll system of mosques, madrasahs hit by ransomware; staff details potentially compromised
The system contained details of staff at dozens of mosques, including their salaries and bank account numbers.
The Islamic Religious Council of Singapore (MUIS) has uncovered a ransomware attack on the payroll systems of mosques and madrasahs under its supervision. The cyber breach, detected on August 30 and 31, saw the SmartHRMS system, provided by Singapore-based firm Avelogic, come under hacker control. The compromised system held sensitive personal data of staff from numerous religious institutions, including names, contact details, salaries, and bank account numbers.
MUIS stated that the incident does not impact public-facing or government services, and business continuity measures are in place to ensure essential HR and payroll functions continue. Affected employees have been provided with necessary guidance. However, the council declined to disclose how many mosques and madrasahs were affected or what information was compromised, citing ongoing investigations.
The ransomware attack either encrypts the data or steals it, demanding a ransom to prevent data leaks or unlock encrypted files. Avelogic confirmed the encryption of its databases, including backups, and stated it could not rule out data theft due to unexplained outbound transfers. However, the firm later claimed it had recovered the latest data set and was aiming to restore systems by September 18.
Avelogic has filed a police report and notified the Personal Data Protection Commission (PDPC), commissioning an independent forensic investigation. The police have also lodged a report and are investigating the data breach.
Written by urgent.news from Straits Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.