{"id":6228,"date":"2025-08-18T10:03:38","date_gmt":"2025-08-18T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/18\/hr-giant-workday-discloses-data-breach-after-hackers-compromise-third-party-crm\/"},"modified":"2025-08-18T10:03:38","modified_gmt":"2025-08-18T10:03:38","slug":"hr-giant-workday-discloses-data-breach-after-hackers-compromise-third-party-crm","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/18\/hr-giant-workday-discloses-data-breach-after-hackers-compromise-third-party-crm\/","title":{"rendered":"HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM"},"content":{"rendered":"<p>    HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Workday, a leading provider of enterprise cloud applications for finance and human resources, has confirmed it was the target of a sophisticated <a href=\"https:\/\/cybersecuritynews.com\/tag\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> campaign that resulted in a data breach via a third-party Customer Relationship Management (CRM) platform.<\/p>\n<p>The company emphasized that the incident did not compromise customer data or tenants.<\/p>\n<p>In a recent disclosure, Workday explained that threat actors are targeting numerous large organizations through elaborate social engineering schemes. <\/p>\n<p>These attacks involve contacting employees via text messages or phone calls while impersonating personnel from human resources or IT departments.<\/p>\n<p>The primary objective of the attackers is to deceive employees into surrendering their account credentials or other sensitive personal information.<\/p>\n<p>Workday\u2019s security team identified that the company had been targeted in this campaign, leading to unauthorized access to some information within its third-party CRM system. <\/p>\n<p>According to the company\u2019s <a href=\"https:\/\/blog.workday.com\/en-us\/protecting-you-from-social-engineering-campaigns-update-from-workday.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">statement<\/a>, the compromised data was primarily \u201ccommonly available business contact information, like names, email addresses, and phone numbers.\u201d It is believed that the threat actors obtained this information to fuel further social engineering scams.<\/p>\n<p>The company confirms that its core systems and customer environments remain secure. \u201cThere is no indication of access to customer tenants or the data within them,\u201d Workday announced, reassuring its extensive client base that its proprietary data was not affected.<\/p>\n<p>Upon detecting the breach, Workday\u2019s cybersecurity team acted swiftly to terminate the unauthorized access and has since implemented additional security measures to prevent similar <a href=\"https:\/\/cybersecuritynews.com\/category\/recent-cybersecurity-incidents\/\" target=\"_blank\" rel=\"noreferrer noopener\">incidents<\/a>. The company is using this event to reinforce security awareness among its employees and the public.<\/p>\n<p>As a reminder to its users and the general public, Workday reiterated its communication policies, stating, \u201cWorkday will never contact anyone by phone to request a password or any other secure details. All official communications from Workday come through our trusted support channels.\u201d<\/p>\n<p>This incident highlights a growing trend where cybercriminals exploit the human element, often the weakest link in the security chain, to infiltrate corporate networks.<\/p>\n<p>By targeting third-party vendors and using deceptive social engineering tactics, attackers can bypass traditional security defenses.<\/p>\n<p>Organizations are urged to enhance employee training and awareness programs to recognize better and report such malicious attempts. For more details on Workday\u2019s security protocols, the company directs customers to its official Security and Trust webpage.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/workday-data-breach\/\">HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/workday-data-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM Workday, a leading provider of enterprise cloud applications for finance and human resources, has confirmed it was the target of a sophisticated social engineering campaign that resulted in a data breach via a third-party Customer Relationship Management (CRM) platform. The company emphasized that the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-6228","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6228"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6228"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6228\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}