A ransomware attack has compromised the payroll system used by mosques and madrasahs under the Islamic Religious Council of Singapore (MUIS), underscoring the growing threat of cyberattacks exploiting third-party vendors. Adrian Hia, Managing Director for Asia Pacific at Kaspersky, emphasised the broader cybersecurity implications, drawing parallels with a similar incident involving the Singapore Land Authority in July.
Hia noted that both incidents involved threat actors targeting service partners to access sensitive data within critical organisations. “This is a particularly effective technique as cybercriminals recognise that government agencies, critical infrastructure operators or even large enterprises are amongst the most heavily defended organisations from a cybersecurity perspective,” he stated.
The attack highlights the need for an ecosystem-wide approach to cybersecurity, especially as cybercriminals increasingly adopt artificial intelligence to enhance the scale and sophistication of their campaigns. Hia stressed the importance of holding external service providers to the same cybersecurity standards as internal environments to ensure robust cyber hygiene and incident response preparedness.
He concluded that strengthening cyber resilience requires collaboration between government agencies, industry leaders, and cybersecurity experts. “It is only through the continued collaboration between all players in the ecosystem that we can ensure the security of all,” Hia said.
As organisations become more digitally connected, the vulnerabilities in their supply chains are expected to increase, making it crucial for all parties involved to work together to mitigate these risks.



