INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Social Engineers Steal Business Contact Details from Workday CRM
| 2025-08-18 14:31 DATA BREACH
Executive Summary
AI-generated
A sophisticated social engineering scam targeted Workday's third-party CRM platform, resulting in the theft of primarily commonly available business contact information such as names, email addresses, and phone numbers. The attackers posed as HR or IT staff to gain access, then slipped in malicious OAuth apps to quietly drain cloud systems. Three notorious cybercrime gangs appear to be collaborating, with ShinyHunters being linked to the incident through a string of recent Salesforce-related heists. Victims include companies such as Adidas and Qantas, among others. The breach was discovered almost two weeks ago on August 6, but Workday has not disclosed how many customers were affected or what measures it took to prevent similar incidents in the future.
Technical Mitigations AI-generated
• Use OAuth apps with strict validation and verification to prevent malicious app installations.
• Monitor for phishing or vishing scams using business contact information, such as names, email addresses, and phone numbers.
• Implement additional security measures internally to protect employees from similar social engineering campaigns.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
gr•••••.three
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Intelligence Sources
The Register - CSO
2025-08-18