• Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
No Result
View All Result
Home Cyber

HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM

Jane Doe by Jane Doe
August 18, 2025
in Cyber
Share on FacebookShare on Twitter

Workday, a leading provider of enterprise cloud applications for finance and human resources, has announced a data breach affecting a third-party Customer Relationship Management (CRM) platform. The company confirmed the incident, which appears to be part of a larger social engineering campaign targeting multiple large organizations. Workday’s core systems and customer data stored in its primary tenants were not affected, the company stated.

The breach, discovered on August 6, was a result of a sophisticated social engineering scheme where attackers contacted Workday employees, posing as internal HR or IT staff. The goal was to trick employees into providing account access or sensitive personal information, which ultimately led to the compromise of the third-party CRM. The specific CRM vendor was not named in Workday’s public disclosure.

According to Workday, the information obtained by the threat actors was limited to “commonly available business contact information,” including names, email addresses, and phone numbers. The company warned that this data could be used to facilitate future social engineering or phishing scams against its customers and partners. Workday has reiterated its policy that it will never contact individuals by phone to request passwords or other secure details.

Read

Gorilla Technology Secures Major AI Government Intelligence Platform Win in Asia

CrowdStrike’s Fal.Con 2025 Event Kicks Off, Focusing on AI and Ecosystem Innovation

While Workday has not confirmed the group responsible, security experts and media reports have linked the incident to the notorious cybercrime group known as ShinyHunters. This group has been implicated in a series of similar attacks on other high-profile companies, including Google, Adidas, and Chanel, where they targeted Salesforce CRM instances through “vishing” (voice phishing) and the exploitation of malicious OAuth apps.

Workday has stated it acted swiftly to cut off the unauthorized access and has since implemented additional safeguards to prevent similar incidents. The company has also begun the process of notifying affected customers and has encouraged all users to be vigilant against unexpected communications requesting sensitive information.

This breach underscores the growing threat of social engineering and the vulnerability of third-party platforms in the corporate supply chain. It serves as a reminder that even companies with robust internal security can be compromised through weaknesses in their external partners and the human element, which remains one of the most difficult attack vectors to defend against.

Previous Post

The $10.5 Trillion Shadow Economy and the Cybersecurity Gold Rush

Next Post

US Seizes $2.8 Million in Crypto from Zeppelin Ransomware Group

Jane Doe

Jane Doe

More Articles

Fujitsu Develops Energy-Efficient Generative AI Technology
Cyber

UN Establishes Global Dialogue on AI Governance to Address AI Risks and Oversight

In a landmark move, the United Nations has launched a new global initiative to establish an international framework for AI...

by Jane Doe
September 8, 2025
Fujitsu Develops Energy-Efficient Generative AI Technology
Cyber

EU Data Act to Become Applicable on September 12, 2025, Regulating Data Access and Sharing

The European Union's Data Act is poised to become applicable on September 12, 2025, marking a significant milestone in the...

by Jane Doe
September 8, 2025
Fujitsu Develops Energy-Efficient Generative AI Technology
Cyber

VirusTotal Finds Hidden Malware Phishing Campaign in SVG Files

In a new and concerning development, security researchers at VirusTotal have identified a sophisticated phishing campaign that uses Scalable Vector...

by Jane Doe
September 8, 2025
Fujitsu Develops Energy-Efficient Generative AI Technology
Cyber

AI-powered Malware Hits Over 2,180 GitHub Accounts in “s1ngularity” Attack

A new and insidious form of cyberattack, leveraging artificial intelligence (AI) to automate and scale malicious activities, is reportedly targeting...

by Jane Doe
September 8, 2025
Next Post
Dubai Launches AI Tech that Lets Passengers Walk Through Immigration Without Showing Passport

US Seizes $2.8 Million in Crypto from Zeppelin Ransomware Group

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Latest News

Hacking AI the Right Way: A Guide to AI Red Teaming

Hacking AI the Right Way: A Guide to AI Red Teaming

May 27, 2025
Researchers Cracked the Encryption Used by DarkBit Ransomware

Researchers Cracked the Encryption Used by DarkBit Ransomware

August 12, 2025
Researchers Cracked the Encryption Used by DarkBit Ransomware

High-severity WinRAR 0-day exploited for weeks by 2 groups

August 12, 2025

Transforming App Development with AI, Part 3: Challenges and Ethical Considerations

March 19, 2025
Exploring AI’s Critical Role in Climate Change at the G7 Summit

Exploring AI’s Critical Role in Climate Change at the G7 Summit

May 28, 2025
Are We Ready for the Next Cyber Storm? Why Staying Passive Is the Greatest Risk

Are We Ready for the Next Cyber Storm?

April 26, 2025
Researchers Cracked the Encryption Used by DarkBit Ransomware

Ghanaian Nationals Extradited for Roles in $100M Romance and Wire Fraud

August 12, 2025
Sumtrix.com

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Navigate Site

  • About
  • Contact
  • Privacy Policy
  • Advertise

Follow Us

No Result
View All Result
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Our website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.