Avelogic Pte Ltd — notice to SmartHRMS customers

Data Incident Notice

Updated 7-Sep-2026 20:00 SGT

Detected
31 August 2026, 8:30am SGT
Status
Databases and backups encrypted; no recovery point
Police report
SPF no. L/20260831/7082, 31 August 2026
PDPC filing
ENF-DBN-260831-0004 Filed by Avelogic as data intermediary
Investigation
Forensic investigation underway

What happened

On 31 August 2026 we identified that the infrastructure hosting SmartHRMS had been affected by a ransomware attack. We isolated the affected systems, revoked remote access, and preserved forensic evidence.

Our SQL databases and all attached backup sets were encrypted. There is no recovery point.

A police report has been lodged with the Singapore Police Force. A forensic investigation is in progress and root cause has not yet been established.

Data

Customer HRMS data — employee records, payroll history and leave data — was held in the affected databases.

We have observed unexplained outbound data transfers in the period before the encryption. Network flow logging was not enabled, so we cannot confirm or rule out that data was taken. We are not in a position to give assurances either way, and we are writing to each affected customer directly with the specific evidence relating to their account.

Regulatory

Avelogic has notified the Personal Data Protection Commission in our capacity as data intermediary. Our filing acknowledgement number is ENF-DBN-260831-0004.

If you are a SmartHRMS customer: the duty to assess this breach and to notify the PDPC and affected individuals rests with your organisation. Our filing does not discharge that obligation. Please take your own legal advice. We are providing each customer with the information needed to support that assessment.

We have withdrawn the guidance on notification exemptions that appeared in our earlier notice. Please disregard it and rely on your own advice. We have written to customers separately on this point.

What we are doing

We have paused rebuilding a new isolated infrastructure separated from the affected environment. Due to preliminary requirements from our forensic investigations, we are not committing to a completion date until we have finalized a feasibility study. Customers will be updated once the investigation closed by 11 Sep 2026.

For affected customers

We are contacting you directly. If you have not heard from us, or need to verify a communication that appears to come from Avelogic, please contact us before acting on it:

Please treat any unexpected message referencing this incident as suspect until verified.