Singapore

Singapore payroll incident: what MUIS says about Avelogic's system

MUIS says payroll alternatives were in place and no ransom was paid. Its statement of no evidence of large data theft is not the same as confirmation that no data was accessed.

By ProtectMyData EditorialPublished Updated 4 min read
Singapore's Marina Bay skyline at dusk, a file photograph providing location context.
Singapore skyline. File photograph, not an affected institution. Photo by Benh LIEU SONG, source, CC BY-SA 4.0. Cropped and resized. This derivative is available under CC BY-SA 4.0.

The story in brief

Which system was affected?
Avelogic's HR and payroll system, used by clients across sectors. MUIS identifies affected community-sector organisations, not every service or resident in Singapore.
Were salaries or public services stopped?
MUIS says alternative payroll arrangements were in place, with no disruption to religious or public-facing services in its 17 September update.
What remains uncertain?
The final scope of data access and theft. MUIS says the investigation had not found evidence of a large amount of data being taken.

A vendor incident affecting several organisations

In a 17 September 2026 media release, the Islamic Religious Council of Singapore, MUIS, confirmed a cybersecurity incident affecting Avelogic's HR and payroll system and clients across different sectors.

Within the community sector, its list includes 48 mosques, four madrasahs, the Islamic Learning Hub and Management Office, known as ILHAM, and Mosque-Madrasah-Wakaf Shared Services, known as MMWSS.

The incident should not be described as a breach of every Singapore resident or every MUIS service. The named organisations are customers or users affected by a vendor-system incident. The official statement does not provide a complete cross-sector customer list.

What is known about staff data

MUIS says Avelogic had recovered the affected data and engaged independent cybersecurity experts. Based on the investigation at that point, there was no evidence that a large amount of data had been taken. It also says stored data was encrypted.

That statement has limits. Recovering data does not establish that an attacker never copied it. Encryption is an additional safeguard, not evidence on its own that every record was unreadable to the attacker. No evidence of large-scale theft is not a final finding of zero exposure.

The Straits Times reports that the system was believed to contain staff names, contact details, salary information and bank account numbers. These are reported categories the system may have held, not a verified list of fields stolen from every employee.

Affected community organisationsSource-backed
MUIS lists 48 mosques, four madrasahs, ILHAM and MMWSS.
No ransom paidSource-backed
MUIS states this and says a police report was made.
Data recovered and investigation continuingSource-backed
MUIS reports recovery, independent experts and ongoing security checks.
All staff data stolen, or no data accessedNot established
Neither conclusion is established by the official update checked.

Payroll continuity is separate from data security

MUIS says alternative payroll arrangements were in place to ensure affected employees received salaries on time. It reports no disruption to religious or public-facing services.

The statement says the affected system would resume operations only after safeguards and security checks were completed. It does not provide a confirmed restart date. This article does not infer that restoration occurred simply because time has passed.

Keeping salaries and services running matters, but it does not settle whether personal data was accessed. Operational recovery and an investigation into confidentiality answer different questions.

Useful steps for employees and organisations

The official release is an organisational update, not an individual exposure checker. If you work for an affected institution, use known workplace HR contacts to ask about authenticated notices and any steps relevant to you.

  1. Verify a payroll message separatelyDo not send identity documents or bank details in response to an unexpected email. Contact HR using a known number or workplace channel.
  2. Check a request to change bank detailsPayroll incidents can be used as a pretext for impersonation. Follow your employer's established verification process, and do not rely on a familiar sender name alone.
  3. Monitor relevant accountsReview salary payments and bank activity. If anything is suspicious, contact your bank and employer promptly through official channels. Do not assume every employee's bank account was compromised.
  4. Protect reused passwordsIf an authenticated notice says credentials were involved, change affected and reused passwords using official sites and enable multi-factor authentication where available. The sources here do not establish that passwords were stolen.

The boundary of public-data protection

A public email exposure scan cannot inspect a private HR platform or identify every person affected by this vendor incident. An existing unrelated breach record is not proof of involvement.

Removing public listings does not delete employer payroll records or recover copied data. Incident-specific workplace and banking advice should be handled separately from ongoing privacy protection.

The Avelogic and MUIS reporting timeline

  1. Vendor detection dates reported

    The Straits Times attributes these dates to Avelogic's incident notice. They are reported dates, not our inspection of vendor logs.

  2. MUIS issues an update

    MUIS describes affected organisations, payroll alternatives, a police report and no ransom payment.

  3. Data scope remains under investigation

    MUIS says there is no evidence of a large amount of data being taken and that security checks continue.

What was checked

What was checked

We checked MUIS's official 17 September media release and The Straits Times' reporting from the same date on 9 October 2026. The official statement takes precedence over stronger claims in an automated news summary.

We have not accessed employee records, vendor logs or attacker material. The article does not invent an affected-person count or a final data-theft finding.

Questions readers ask

Were all Singapore residents affected?

No such claim is supported. This concerns a vendor's HR and payroll system and its clients. MUIS names affected organisations within the community sector.

Does encryption prove staff data was safe?

No. MUIS describes encryption as an additional safeguard. The investigation's final conclusions about access and theft are not established in the update checked.

Were salaries delayed?

MUIS says alternative arrangements were in place to ensure salaries continued on time. That is its 17 September organisational assessment, not an audit of every payment.

Sources

  1. Cybersecurity incident affecting Avelogic's HR and payroll system and clients across different sectorsMUIS, official media release, 17 September 2026
  2. No evidence a large amount of data compromised from HR system hit by ransomware, says MUISThe Straits Times, 17 September 2026

Published 9 October 2026. Sources checked 9 October 2026. Last updated 9 October 2026. We do not link to attacker material.

The short version

MUIS confirms a vendor-system incident and continuity measures. Its initial assessment does not prove either wholesale staff-data theft or zero exposure. Use known HR channels, verify payroll requests and keep the unfinished investigation in view.