19th August 2025 Cyber Update: HR Giant Workday Hit by Social Engineering Attack Exposing 70+ Million Users

HR giant Workday confirms data breach affecting 70+ million users worldwide after hackers infiltrated third-party CRM platform via social engineering. Attack part of broader ShinyHunters campaign targeting major corporations through Salesforce systems.

19th August 2025 Cyber Update: HR Giant Workday Hit by Social Engineering Attack Exposing 70+ Million Users
audio-thumbnail
Today’s Cyber Update
0:00
/101.12

Cyber News Centre's cyber update for 19th August 2025: Workday has confirmed a significant data breach affecting its third-party customer relationship management platform, potentially impacting over 70 million users worldwide through sophisticated social engineering tactics.

Major HR Technology Provider Compromised

Workday is a cloud-based enterprise software company specializing in human capital management, financial management, and planning applications. The S&P 500 constituent reported over $8.4 billion in revenue last year and serves more than 11,000 organizations globally, including over 60% of Fortune 500 companies.

The Update and Why It Matters

Update: Workday disclosed on Friday, August 15, 2025, that threat actors infiltrated its third-party customer relationship management platform through a sophisticated social engineering campaign. The breach, discovered on August 6, exposed business contact information including names, email addresses, and phone numbers stored in the CRM system.

The company stated, “We want to let you know about a recent social engineering campaign targeting many large organizations, including Workday. We recently identified that Workday had been targeted and threat actors were able to access some information from our third-party CRM platform. There is no indication of access to customer tenants or the data within them.”

The incident has been linked to the ShinyHunters extortion group, which has been targeting Salesforce CRM instances through voice phishing and OAuth manipulation. Attackers typically impersonate IT or HR personnel, convincing employees to authorize malicious applications that grant persistent database access. Once inside, they exfiltrate company data for extortion purposes.

Workday terminated the unauthorized access, introduced additional safeguards, and reminded customers that it never requests passwords or secure details via phone.

Why it Matters: This breach highlights how third-party platforms can become entry points for attackers, with one compromised CRM exposing data across multiple organizations. For Australian businesses, the incident is a reminder that global supply chain breaches can quickly ripple into local operations. The ShinyHunters campaign also illustrates the growing sophistication of social engineering, where human deception is now as dangerous as technical exploits.


Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Cyber News Centre.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.