Home Technology Security Workday suffers data breach

Workday suffers data breach

Workday warned customers of a social engineering campaign after the company was hit with a data breach.

In an August 15 blog post, Workday said it had been targeted and threat actors were able to access “some information” from from its third-party CRM platform.

“There is no indication of access to customer tenants or the data within them. We acted quickly to cut the access and have added extra safeguards to protect against similar incidents in the future,” the company said.

The data stolen was “primarily commonly available business contact information, like names, email addresses, and phone numbers, potentially to further their social engineering scams.”

Workday cautioned its customers to be more vigilant, as threat actors may “contact employees by text or phone pretending to be from human resources or IT.”

“Their goal is to trick employees into giving up account access or their personal information,” Workday noted.

The company reiterated that it will never contact anyone by phone to request a password or any other secure details, and that all official communications from Workday will come through its trusted support channels.

According to a security expert, the incident reflected a troubling trend across enterprise software vendors, which “appears connected to a broader wave of recent attacks similarly targeting CRM systems at multiple global enterprises via sophisticated social engineering and OAuth-based tactics.”

“Even when primary systems remain intact, external integration points can serve as gateways for attackers. These third-party ecosystems often are not subjected to the same level of scrutiny and control as the internal environments,” noted Darren Guccione, CEO And Co-Founder, Keeper Security.

Guccione suggested that organisations should view third-party applications, vendor tools and CRM systems as integral extension points of their own attack surface, restrict access to what is necessary, and implement Privileged Access Management (PAM), zero-trust architectures and zero-knowledge approaches to limit exposure.

- Advertisement -