Workday Breach Likely Linked to ShinyHunters Salesforce Attacks
ID: 312a8d5b-4499-5c22-81fc-a1056c12e7e1
STIX ID: report--312a8d5b-4499-5c22-81fc-a1056c12e7e1
Feed Name: Dark Reading
Date Published: 2025-08-18
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
**Executive summary:** Workday confirmed a compromise of a third-party CRM via a social-engineering campaign likely tied to the ShinyHunters extortion group, which accessed commonly available business contact information (names, emails, phone numbers) but — according to Workday — not customer tenant data; the incident is part of a wider series of attacks targeting Salesforce instances at multiple large organizations and highlights the use of impersonation, phishing/vishing, and vendor supply-chain pivoting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
