A payroll and human resources system used by mosques and madrasahs in Singapore has been hit by a ransomware attack, potentially affecting sensitive information belonging to employees.
The Islamic Religious Council of Singapore (MUIS) confirmed on Tuesday, 15 September, that a cybersecurity incident had affected a human resource management system operated by Singapore software company Avelogic.
The affected platform is SmartHRMS, which handles functions such as payroll and employee records.
MUIS said it is working with affected organisations, Avelogic and the relevant authorities on follow-up action.
Staff Salary and Bank Details May Be Involved
According to The Straits Times, the affected system is believed to have contained information belonging to staff at dozens of mosques and madrasahs.
This included names, contact details, salaries and bank account numbers.
MUIS did not disclose how many mosques, madrasahs or employees were affected, or specify exactly what information may have been compromised, citing ongoing investigations.
Avelogic said customer information held in the affected databases included employee records, payroll history and leave data.
However, the company said in its latest update that core sensitive fields in SmartHRMS remained protected by encryption at the application level.
This means the fact that information was stored in an affected database does not necessarily mean hackers managed to obtain readable copies of all that information.
Ransomware Encrypted Databases and Backups
Avelogic said it detected the ransomware incident on 31 August.
Ransomware is malicious software used to lock or encrypt computer systems and data. Attackers typically demand payment in exchange for restoring access, although some ransomware groups also steal information and threaten to release it.
An earlier Avelogic notice said its SQL databases and attached backup sets had been encrypted, leaving it without a recovery point at that stage.
The company also detected unexplained outbound data transfers before the encryption occurred and initially said it could neither confirm nor rule out whether information had been taken.
However, an updated investigation found no evidence of bulk data exfiltration, based on available Amazon Web Services network information covering confirmed attacker activity on 30 and 31 August.
In simpler terms, investigators have not found evidence that the attackers downloaded large amounts of data from the system.
Avelogic also said it had successfully recovered the latest data set and was targeting 18 September to bring its new system online, with other functions to be restored progressively afterwards.
Public Services Not Affected
MUIS said the incident has not affected public-facing or government services.
Business continuity measures have instead been put in place so that essential HR and payroll functions can continue.
Affected employees are also being provided with guidance and support.
The Straits Times reported, citing an affected individual, that accounting staff were unable to access the system after the attack and had to process salaries manually.
MUIS did not say whether any ransom had been paid.
Police and PDPC Investigating
Avelogic lodged a police report on 31 August and also notified the Personal Data Protection Commission (PDPC) in its role as a data intermediary.
The company subsequently appointed cybersecurity firm Black Panda to carry out an independent forensic investigation.
Police confirmed that a report had been made and that investigations are ongoing.
The PDPC also told The Straits Times that it was aware of Avelogic’s data breach notification and was investigating the matter.