Workday Data Breach: Salesforce Attack Fallout
:
Workday Hit by Salesforce Breach as ShinyHunters Group Expands Attack Campaign
Pleasanton, California – Human resources giant Workday has disclosed a data breach stemming from a social engineering attack targeting a third-party customer relationship management (CRM) platform. The incident is part of a wider wave of attacks linked to the notorious hacking group ShinyHunters, which has recently targeted numerous high-profile companies.
Headquartered in Pleasanton, California, Workday serves over 11,000 organizations globally, including more than 60% of the Fortune 500. The company, with over 19,300 employees across North America, EMEA, and APJ, confirmed the breach in a blog post on Friday.
“We want to let you know about a recent social engineering campaign targeting many large organizations, including Workday,” the company stated. “We recently identified that Workday had been targeted and threat actors were able to access some details from our third-party CRM platform. There is no indication of access to customer tenants or the data within them.”
However, the attackers did gain access to business contact information, including names, email addresses, and phone numbers. Workday warns this data could be used in subsequent phishing and social engineering scams. The breach was discovered on august 6th, according to a notification sent to potentially affected customers.
Part of a Larger trend
Workday is the latest victim in a series of attacks attributed to ShinyHunters, a group known for data extortion.The group targets Salesforce CRM instances through elegant social engineering and voice phishing tactics.
Recent targets include Adidas, Qantas, Allianz Life, Louis Vuitton, Dior, Tiffany & Co., and even Google. The attackers gain access by tricking employees into linking a malicious app to their company’s Salesforce instance. Once inside,they download databases and then use the stolen information to extort the companies.
What This Means for You
While Workday states customer data within their systems remains secure, the exposure of contact information is a serious concern.Individuals who are customers or contacts of Workday clients should be extra vigilant about potential phishing attempts.
Here’s what to watch out for:
Unexpected Communications: Be wary of unsolicited emails, texts, or phone calls, especially those requesting personal information or account access.
Verify Sender identity: Always independently verify the identity of anyone requesting sensitive information. Do not click on links or open attachments from unkown sources.
* Report Suspicious Activity: If you suspect a phishing attempt, report it to yoru IT department and the company the interaction appears to be from.
This incident underscores the growing threat of social engineering attacks and the importance of robust security awareness training for all employees. As companies increasingly rely on third-party platforms, securing these connections becomes paramount in protecting sensitive data.
