< Back to all clusters
[TECHNOLOGY] · Singapore · 3 sources

started · updated

MUIS staff data exposed in third-party vendor breach

A cybersecurity incident involving a third-party payroll and human resource system has exposed the personal and financial data of staff at mosques and madrasahs under the Islamic Religious Council of Singapore (MUIS).

The breach targeted SmartHRMS, an outsourced platform used by various religious institutions. The vendor reported detecting ransomware activity on August 31, 2026. While the vendor's internal investigation found no evidence of bulk data exfiltration, the system is believed to have contained sensitive information, including staff names, contact details, salaries, and bank account numbers.

MUIS confirmed that its public-facing and government services remained unaffected by the incident. The vendor has filed a police report and notified Singapore’s Personal Data Protection Commission (PDPC). Cybersecurity experts have noted that such incidents highlight the risks of vendor-based compromises, where a single breach can cascade across multiple institutions, and have renewed calls for organizations to adopt zero trust security architectures.

Entities

Islamic Religious Council of Singapore · Keeper Security · MUIS · Personal Data Protection Commission · SmartHRMS