Avelogic Pte Ltd — notice to SmartHRMS customers
Data Incident Notice
Updated 7-Sep-2026 20:00 SGT
- Detected
- 31 August 2026, 8:30am SGT
- Status
- Databases and backups encrypted; no recovery point
- Police report
- SPF no. L/20260831/7082, 31 August 2026
- PDPC filing
- ENF-DBN-260831-0004 Filed by Avelogic as data intermediary
- Investigation
- Forensic investigation underway
What happened
On 31 August 2026 we identified that the infrastructure hosting SmartHRMS had been affected by a ransomware attack. We isolated the affected systems, revoked remote access, and preserved forensic evidence.
Our SQL databases and all attached backup sets were encrypted. There is no recovery point.
A police report has been lodged with the Singapore Police Force. A forensic investigation is in progress and root cause has not yet been established.
Data
Customer HRMS data — employee records, payroll history and leave data — was held in the affected databases.
We have observed unexplained outbound data transfers in the period before the encryption. Network flow logging was not enabled, so we cannot confirm or rule out that data was taken. We are not in a position to give assurances either way, and we are writing to each affected customer directly with the specific evidence relating to their account.
Regulatory
Avelogic has notified the Personal Data Protection Commission in our capacity as data intermediary. Our filing acknowledgement number is ENF-DBN-260831-0004.
If you are a SmartHRMS customer: the duty to assess this breach and to notify the PDPC and affected individuals rests with your organisation. Our filing does not discharge that obligation. Please take your own legal advice. We are providing each customer with the information needed to support that assessment.
We have withdrawn the guidance on notification exemptions that appeared in our earlier notice. Please disregard it and rely on your own advice. We have written to customers separately on this point.
What we are doing
We have paused rebuilding a new isolated infrastructure separated from the affected environment. Due to preliminary requirements from our forensic investigations, we are not committing to a completion date until we have finalized a feasibility study. Customers will be updated once the investigation closed by 11 Sep 2026.
For affected customers
We are contacting you directly. If you have not heard from us, or need to verify a communication that appears to come from Avelogic, please contact us before acting on it:
Please treat any unexpected message referencing this incident as suspect until verified.