A cybersecurity incident at the Islamic Religious Council of Singapore (MUIS) has renewed calls for organisations across the region to lock down third-party vendor access, after a breach at a payroll system operator exposed the financial and personal data of staff at mosques and madrasahs under its purview.

MUIS confirmed on 15 September that a cybersecurity incident had affected SmartHRMS, a human resource and payroll system operated by a third-party vendor. The system is believed to have held staff names, contact details, salaries and bank account numbers, though MUIS has not confirmed the exact data types or number of people affected.

The vendor said it detected ransomware activity on 31 August, lodged a police report and notified Singapore’s Personal Data Protection Commission (PDPC), adding that its investigation found no evidence of bulk data exfiltration. MUIS said its public-facing and government services remain unaffected.

A single vendor compromise, dozens of institutions exposed

“The cybersecurity incident affecting the human resource and payroll system used by mosques and madrasahs under the Islamic Religious Council of Singapore demonstrates how quickly the impact of a single vendor compromise can cascade across institutions,” said Takanori Nishiyama, senior vice president for APAC and country manager for Japan at Keeper Security. “The affected system reportedly held names, contact details, salaries and bank account numbers for employees across dozens of religious institutions, and that combination of identity and financial data is exactly what cybercriminals seek for fraud and impersonation.”

Nishiyama noted that religious and community bodies such as MUIS, which administers mosques, oversees madrasah education and certifies Halal products relied upon by consumers and businesses in Singapore, are deliberate targets for cybercriminals. He added that counterparts in Malaysia, Indonesia, Brunei and the Philippines hold comparable mandates, meaning any organisation across the region that processes personal data at scale faces the same exposure.

Third parties involved in nearly half of breaches

The incident originated within a system run by a third-party vendor rather than MUIS itself, a pattern Nishiyama said is becoming increasingly common. He pointed to Verizon’s 2026 Data Breach Investigations Report, which found that a third party was involved in 48 per cent of breaches globally — a trend he described as a widening pattern across the region rather than an isolated failure.

“Outsourcing a function does not outsource accountability for the data it processes.”

Singapore’s public sector is already moving towards zero-trust security through the Government Zero Trust Architecture framework, and Nishiyama argued those principles must extend to every vendor relationship. He called for organisations to verify and audit every point of third-party access, and enforce multi-factor authentication and privileged access management for every vendor account.

Turning a vendor compromise into a contained incident

Least-privilege and just-in-time access, Nishiyama said, ensure vendors hold entitlements only when required to perform their duties, while every vendor session should be authenticated, authorised and auditable, with dormant accounts removed as soon as a contract ends.

“Applied consistently, these controls turn a vendor compromise into a contained incident rather than a large-scale data breach,” he said.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading