Avelogic Pte Ltd — notice to SmartHRMS customers
Data Incident Notice
Updated 2-Sep-2026 08:00 SGT
- Detected
- 31 August 2026, 8:30am SGT
- Status
- Databases and backups encrypted; no recovery point
- Police report
- SPF no. L/20260831/7082, 31 August 2026
- PDPC filing
- ENF-DBN-260831-0004 Filed by Avelogic as data intermediary
- Investigation
- Forensic investigation underway
What happened
On 31 August 2026 we identified that the infrastructure hosting SmartHRMS had been affected by a ransomware attack. We isolated the affected systems, revoked remote access, and preserved forensic evidence.
Our SQL databases and all attached backup sets were encrypted. There is no recovery point.
A police report has been lodged with the Singapore Police Force. We will not be paying the ransom. A forensic investigation is in progress and root cause has not yet been established.
Data
Customer HRMS data — employee records, payroll history and leave data — was held in the affected databases.
We have observed unexplained outbound data transfers in the period before the encryption. Network flow logging was not enabled, so we cannot confirm or rule out that data was taken. We are not in a position to give assurances either way, and we are writing to each affected customer directly with the specific evidence relating to their account.
Regulatory
Avelogic has notified the Personal Data Protection Commission in our capacity as data intermediary. Our filing acknowledgement number is ENF-DBN-260831-0004.
If you are a SmartHRMS customer: the duty to assess this breach and to notify the PDPC and affected individuals rests with your organisation. Our filing does not discharge that obligation. Please take your own legal advice. We are providing each customer with the information needed to support that assessment.
We have withdrawn the guidance on notification exemptions that appeared in our earlier notice. Please disregard it and rely on your own advice. We have written to customers separately on this point.
What we are doing
We are rebuilding on new, isolated infrastructure separated from the affected environment, and will provide data reconstruction and payroll continuity support to affected customers. We are not committing to a completion date until root cause is confirmed. Customers are being updated directly on timing.
Our earlier instruction to return reconstruction data by password-protected email has been withdrawn. Revised secure transfer arrangements have been sent to customers.
For affected customers
We are contacting you directly. If you have not heard from us, or need to verify a communication that appears to come from Avelogic, please contact us before acting on it:
Please treat any unexpected message referencing this incident as suspect until verified.