INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Social Engineers Steal Business Contact Details from Workday CRM

| 2025-08-18 14:31 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A sophisticated social engineering scam targeted Workday, a HR SaaS giant, on August 6, 2025, with attackers gaining access to one of its third-party CRM platforms. The attackers posed as IT or HR staff and slipped in malicious OAuth apps to quietly drain cloud systems, ultimately making off with "some information" from the unnamed CRM system, including primarily commonly available business contact information like names, email addresses, and phone numbers. This incident is linked to ShinyHunters, a crew blamed for recent Salesforce-related heists, which has been swapping tips with other notorious cybercrime groups in a shared Telegram hangout. The breach was discovered almost two weeks later on August 18, when Workday notified affected customers that some of their business contact information had been accessed, and the company took additional security measures to protect its employees.
Technical Mitigations AI-generated
• Patch the ShinyHunters OAuth apps used in social engineering attacks to prevent malicious app installations. • Implement additional security measures internally, such as multi-factor authentication and access controls, to protect Workday employees from similar campaigns. • Monitor customer data for signs of phishing or vishing scams using indicators like "primarily commonly available business contact information" accessed by attackers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎2025/08/18
Threat actors using social engineering tactics successfully targeted Workday, obtaining primarily commonly available business contact information.
threat_actor Scattered Spider
Intelligence Sources