Avelogic Pte Ltd — notice to SmartHRMS customers

Data Incident Notice

Updated 2-Sep-2026 08:00 SGT

Detected
31 August 2026, 8:30am SGT
Status
Databases and backups encrypted; no recovery point
Police report
SPF no. L/20260831/7082, 31 August 2026
PDPC filing
ENF-DBN-260831-0004 Filed by Avelogic as data intermediary
Investigation
Forensic investigation underway

What happened

On 31 August 2026 we identified that the infrastructure hosting SmartHRMS had been affected by a ransomware attack. We isolated the affected systems, revoked remote access, and preserved forensic evidence.

Our SQL databases and all attached backup sets were encrypted. There is no recovery point.

A police report has been lodged with the Singapore Police Force. We will not be paying the ransom. A forensic investigation is in progress and root cause has not yet been established.

Data

Customer HRMS data — employee records, payroll history and leave data — was held in the affected databases.

We have observed unexplained outbound data transfers in the period before the encryption. Network flow logging was not enabled, so we cannot confirm or rule out that data was taken. We are not in a position to give assurances either way, and we are writing to each affected customer directly with the specific evidence relating to their account.

Regulatory

Avelogic has notified the Personal Data Protection Commission in our capacity as data intermediary. Our filing acknowledgement number is ENF-DBN-260831-0004.

If you are a SmartHRMS customer: the duty to assess this breach and to notify the PDPC and affected individuals rests with your organisation. Our filing does not discharge that obligation. Please take your own legal advice. We are providing each customer with the information needed to support that assessment.

We have withdrawn the guidance on notification exemptions that appeared in our earlier notice. Please disregard it and rely on your own advice. We have written to customers separately on this point.

What we are doing

We are rebuilding on new, isolated infrastructure separated from the affected environment, and will provide data reconstruction and payroll continuity support to affected customers. We are not committing to a completion date until root cause is confirmed. Customers are being updated directly on timing.

Our earlier instruction to return reconstruction data by password-protected email has been withdrawn. Revised secure transfer arrangements have been sent to customers.

For affected customers

We are contacting you directly. If you have not heard from us, or need to verify a communication that appears to come from Avelogic, please contact us before acting on it:

Please treat any unexpected message referencing this incident as suspect until verified.