A human resources (HR) management system used by the Islamic Religious Council of Singapore (MUIS) has reportedly been hacked by ransomware.
MUIS told The Straits Times (ST) that the delivery of services would not be affected by the hacking of the system, which handles the payroll of staff at mosques and madrasahs.
Source: Google Maps
MUIS confirmed with ST on Tuesday (15 Sept) that a cybersecurity incident had occurred involving an HR system operated by Singapore-based provider Avelogic.
It is working on necessary follow-up actions with the affected organisations, Avelogic and the relevant authorities, it said.
The delivery of public-facing or government services is not affected as business continuity arrangements have been implemented, it noted, adding that essential HR and payroll functions will be supported and affected employees are also being provided with “necessary guidance and support”.
MUIS declined to provide more information as investigations are ongoing.
On its website, Avelogic posted a security incident update involving its SmartHRMS system, a CPF-compliant payroll and HR management system that automates payroll, leave, claims, employee self-service and attendance.
The update on Monday (14 Sept) said the period of “confirmed threat actor activity” was from 30 Aug to 31 Aug.
Source: Chirayu Trivedi on Unsplash. Photo for illustration purposes only.
An independent forensic investigation, commissioned on 3 Sept, found no evidence of bulk data exfiltration, while core sensitive data fields within the system remain protected by application-layer encryption.
Avelogic did not identify the client affected, but said that it had notified the Personal Data Protection Commission (PDPC) in its legal capacity as a data intermediary.
A police report was also lodged on 31 Aug.
As part of its structured recovery process, Avelogic has successfully recovered the last updated data set.
The new system is targeted to be up by Friday (18 Sept), while other components will be brought back online “progressively thereafter”, it added.
MUIS handles the accounts of 69 mosques, three madrasahs and two wakafs (Islamic religious endowments) through a committee known as Mosque-Madrasah-Wakaf Shared Services (MMWSS).
MMWSS helps produce Income-Expenditure statements for Mosque Management Boards and manages interventional fundraising for MUIS entities, among other duties.
It supplied the SmartHRMS system to mosques and madrasahs, according to ST.
Source: Google Maps
A source told the paper that after the system was hacked, accounting staff could not log in and had to process payroll manually.
A ransomware attack involves hackers either stealing the data and threatening to release it, or locking the data, forcing victims to pay a ransom to prevent leakage or to unlock the data.
The system affected reportedly held sensitive staff information, including names, contact details, salaries and bank account numbers.
Also read: S’pore under attack by cyber espionage group, critical infrastructure under threat: Shanmugam
Have news you must share? Get in touch with us via email at news@mustsharenews.com.
Featured image adapted from Google Maps.