logo

Workday Breach Likely Linked to ShinyHunters Salesforce Attacks

ID: 312a8d5b-4499-5c22-81fc-a1056c12e7e1

STIX ID: report--312a8d5b-4499-5c22-81fc-a1056c12e7e1

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-08-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

**Executive summary:** Workday confirmed a compromise of a third-party CRM via a social-engineering campaign likely tied to the ShinyHunters extortion group, which accessed commonly available business contact information (names, emails, phone numbers) but — according to Workday — not customer tenant data; the incident is part of a wider series of attacks targeting Salesforce instances at multiple large organizations and highlights the use of impersonation, phishing/vishing, and vendor supply-chain pivoting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.