Skip to main content
See every side of every news story
Published loading...Updated

Workday Confirms CRM Breach via Social Engineering

Attackers used social engineering to access customer data via malicious OAuth apps on Salesforce, affecting over 11,000 organizations including luxury brands and Workday, with no customer tenants compromised.

  • Workday, a human resources software firm, confirmed a data breach on August 6 after attackers accessed a third-party CRM platform from its Pleasanton, CA offices.
  • The breach occurred through a social engineering campaign where attackers posed as HR or IT staff to trick employees, linked to the ShinyHunters extortion group.
  • The attackers accessed mostly routine professional contact details, including individual identities, electronic mail contacts, and telephone numbers, which could be exploited for future phishing or voice-based social engineering attacks.
  • Workday responded promptly by restricting access and implementing additional security measures, emphasizing that there is no evidence indicating any compromise of customer data within their platform or impact on customer accounts.
  • The breach highlights ongoing sophisticated cyberattacks targeting Salesforce-hosted CRM systems, suggesting continued vigilance and preparedness are critical for organizations.
Insights by Ground AI
Does this summary seem wrong?
Podcasts & Opinions

15 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 83% of the sources are Center
83% Center

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

PYMNTS.com broke the news in on Sunday, August 17, 2025.
Sources are mostly out of (0)

Similar News Topics

News
For You
Search
BlindspotLocal