Recommended Free Tools
Workday disclosed in August 2025 that attackers used phone- and text-based social engineering to access information in a third-party CRM platform used by the company. Workday said the exposed information was primarily business contact data—names, email addresses and phone numbers—and that it had found no indication that customer Workday tenants or the data inside them were accessed.
The incident resembled a 2025 Salesforce-focused vishing campaign associated by Google Threat Intelligence with tracked clusters including UNC6040. However, Workday did not publicly identify the attackers, and a direct link to ShinyHunters or the same operators remains unconfirmed. This is an explainer of an August 2025 incident, not a newly reported August 2026 breach.
As an Amazon Associate I earn from qualifying purchases.
What Workday confirmed
Workday said threat actors gained access to an unnamed third-party CRM platform after impersonating HR or IT personnel in calls and text messages. The company said it removed the unauthorized access and added safeguards.
Workday’s notice does not name the CRM vendor or provide a detailed forensic timeline. Contemporary reporting said Workday detected the activity on August 6, 2025; that date should be treated as reported detection timing rather than a fully documented public forensic timeline. Workday disclosed the incident during August 2025.
#1 Best Overall
- THE ALTERNATIVE: The Office Suite Package is the perfect alternative to MS Office. It offers you word processing as well as spreadsheet analysis and the creation of presentations.
- LOTS OF EXTRAS:✓ 1,000 different fonts available to individually style your text documents and ✓ 20,000 clipart images
- EASY TO USE: The highly user-friendly interface will guarantee that you get off to a great start | Simply insert the included CD into your CD/DVD drive and install the Office program.
- ONE PROGRAM FOR EVERYTHING: Office Suite is the perfect computer accessory, offering a wide range of uses for university, work and school. ✓ Drawing program ✓ Database ✓ Formula editor ✓ Spreadsheet analysis ✓ Presentations
- FULL COMPATIBILITY: ✓ Compatible with Microsoft Office Word, Excel and PowerPoint ✓ Suitable for Windows 11, 10, 8, 7, Vista and XP (32 and 64-bit versions) ✓ Fast and easy installation ✓ Easy to navigate
Most importantly for customers, Workday said there was no indication that attackers accessed customer tenants or the data stored inside them. The available evidence therefore supports a limited compromise of a business system used by Workday—not a confirmed breach of Workday’s production environments or every customer’s HR platform.
Workday’s customer notice says the company does not call customers to request passwords or other secure information.
What information was accessed?
| Confirmed or stated | Not publicly established |
|---|---|
| Names | Payroll data |
| Email addresses | Benefits or employee records |
| Phone numbers | Workday customer-tenant data |
| Commonly available business contact information | Credentials, MFA secrets or API tokens |
| Access to a third-party CRM used by Workday | The number of affected records or whether all accessed data was exfiltrated |
“Accessed” should not automatically be read as “every record was copied.” The public disclosures do not establish the full scope of data viewed or taken, nor do they say that sensitive HR, payroll, financial or employee-record information was exposed.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Similarly, references to Workday’s broad customer community—sometimes reported as roughly 70 million users—must not be mistaken for a confirmed victim count. No such number was established for this incident.
Rank #2
How the attack worked: vishing, not a demonstrated software exploit
Vishing is voice phishing: an attacker uses a phone call, often supported by text messages, to impersonate a trusted person and manipulate a target into revealing information or granting access.
In Workday’s account, attackers posed as HR or IT personnel. The company has not publicly described the exact technical sequence after the social-engineering contact. It has not, in the available notice, attributed the incident to a particular malware family, a Workday software vulnerability, a specific OAuth authorization, or a particular data-export tool.
That distinction matters. Phone-based impersonation can defeat otherwise strong cloud controls when employees or help-desk staff approve password resets, MFA changes, new-device enrollment or access requests based on a convincing conversation. Caller ID, internal terminology and urgency are not reliable proof of identity.
Why the Salesforce attacks are being mentioned
The suspected connection is based on similarities in method and timing, not a public confirmation that Workday and Salesforce were breached by the same group.
Rank #3
- Pre-designed templates for both business and personal use
- 10,000 clipart images and 100 fonts
- Notes table for history and to-do items
- Sort, filter and index
- Calculation & totaling
Google Threat Intelligence described a contemporaneous Salesforce-focused campaign in which attackers impersonated IT support and persuaded victims to authorize malicious or modified connected applications. Some activity involved tools resembling Salesforce Data Loader. Google said the campaign did not exploit a vulnerability inherent in Salesforce; it manipulated users and SaaS access workflows instead.
Workday’s incident had several similarities:
- Phone-based impersonation of IT or support personnel
- Social engineering rather than a publicly demonstrated vendor software exploit
- Targeting of valuable SaaS or CRM information
- Potential use of business contact data to support additional phishing
But the precise Workday attack chain is not public. It would be inaccurate to say that Salesforce was the affected Workday CRM, that Workday suffered a Salesforce breach, or that the same technical process was proven in both cases.
Google’s analysis is available in “The Cost of a Call.”
Was ShinyHunters responsible?
There is no confirmed public attribution by Workday. The ShinyHunters connection was suspected by outside observers because the incident resembled Salesforce-related intrusions and later extortion activity associated with the ShinyHunters name.
Rank #4
The labels require care:
- ShinyHunters is a criminal brand used in extortion communications and data-leak claims.
- UNC6040 is Google Threat Intelligence’s designation for a financially motivated cluster observed using vishing to compromise Salesforce environments.
- UNC6240 refers to a cluster Google associated with later extortion activity following some intrusions and with actors claiming the ShinyHunters identity.
These labels do not necessarily describe one unified organization. Google has cautioned that apparent overlaps can reflect associated actors, criminal partnerships, shared infrastructure, impersonation or common tactics.
A January 2026 Google/Mandiant report described an expansion of ShinyHunters-branded SaaS data theft involving additional tracked clusters, including UNC6661, UNC6671 and UNC6240. That later activity provides context for the broader threat, but it does not prove that any of those clusters caused the 2025 Workday incident. See Google’s 2026 report.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What Workday customers should do now
Even without evidence that customer tenants were accessed, the incident is relevant because exposed contact information can make later fraud more convincing. Workday customers should treat it as an identity and phishing-risk event.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Warn staff about impersonation. Tell employees that unsolicited calls or texts claiming to be from Workday, HR, payroll, IT or customer support should be treated as suspicious.
- Never disclose secrets by phone. Employees should not provide passwords, MFA codes, recovery codes, API tokens or security answers to a caller.
- Verify independently. End the call and use a known, independently retrieved support or internal contact channel. Do not rely on a number supplied by the caller or in the same message.
- Strengthen account recovery. Require dual approval or out-of-band confirmation for password resets, MFA changes, recovery-detail changes, new-device enrollment and privileged-account recovery.
- Review identity activity. Check identity-provider, help-desk and Workday administrative logs for unusual successful sessions, new authenticators, changed recovery details, newly created users and privilege changes.
- Audit connected applications. Review OAuth grants, integrations, service accounts and unusual data exports. Remove unused or unapproved connections.
- Use phishing-resistant MFA. Prioritize FIDO2/WebAuthn security keys or passkeys for administrators, help-desk personnel and other high-value users. Google and Mandiant have emphasized that stronger authentication must be paired with secure recovery procedures.
- Independently verify payroll changes. Require a separate confirmation before changing employee bank details, payment instructions or other financially sensitive records.
Security keys from vendors such as Yubico and authentication controls from providers such as Okta or Microsoft Entra ID may support this strategy, but no product replaces callback verification, least privilege and disciplined recovery workflows.
Best Value
Why the incident matters beyond Workday
The exposed information may have been commonly available business contact data, but that does not make it harmless. A name, phone number, job title or corporate email address can help an attacker sound legitimate, identify administrators and construct a targeted pretext.
The larger lesson is that third-party systems around a SaaS platform can be valuable even when the core tenant remains isolated. CRM records, help-desk systems, identity providers, support portals and integration consoles may contain the reconnaissance needed to attack a more sensitive account later.
Organizations also commonly monitor failed logins while overlooking successful but unusual activity: a new authenticator, a recovery change, an unexpected OAuth grant or a bulk export performed after a convincing support call.
Timeline
- June 4, 2025: Google published research on UNC6040’s Salesforce-focused vishing activity.
- August 5, 2025: Google said one of its Salesforce instances was affected by similar activity and that retrieved data was limited to basic business information.
- August 6, 2025: Contemporary reporting identified this as Workday’s detection date.
- August 2025: Workday published its customer-facing notice about the third-party CRM incident.
- January 30, 2026: Google/Mandiant reported an expansion of ShinyHunters-branded SaaS data-theft operations involving multiple tracked clusters.
What remains unknown
- The identity of the CRM vendor
- The number of affected records
- Whether attackers copied all or only some accessed information
- Whether credentials or authentication information were exposed
- The identities or number of affected employees
- Whether regulators or law enforcement were notified
- Whether the attackers attempted extortion
- Whether any customer was separately targeted using the exposed contact information
Those gaps are why the most accurate description is a limited third-party CRM compromise caused by social engineering. It is not evidence, based on the cited disclosures, that Workday’s customer tenants were breached, that payroll records were exposed, or that ShinyHunters definitely conducted the attack.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




