DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Workday’s Third-Party CRM Was Hit by Hackers; Salesforce Link Remains Unconfirmed

Workday disclosed a social-engineering compromise of a third-party CRM, not a confirmed breach of customer Workday tenants. The suspected Salesforce and ShinyHunters connection remains unproven.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Workday disclosed in August 2025 that attackers used phone- and text-based social engineering to access information in a third-party CRM platform used by the company. Workday said the exposed information was primarily business contact data—names, email addresses and phone numbers—and that it had found no indication that customer Workday tenants or the data inside them were accessed.

The incident resembled a 2025 Salesforce-focused vishing campaign associated by Google Threat Intelligence with tracked clusters including UNC6040. However, Workday did not publicly identify the attackers, and a direct link to ShinyHunters or the same operators remains unconfirmed. This is an explainer of an August 2025 incident, not a newly reported August 2026 breach.

As an Amazon Associate I earn from qualifying purchases.

What Workday confirmed

Workday said threat actors gained access to an unnamed third-party CRM platform after impersonating HR or IT personnel in calls and text messages. The company said it removed the unauthorized access and added safeguards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Workday’s notice does not name the CRM vendor or provide a detailed forensic timeline. Contemporary reporting said Workday detected the activity on August 6, 2025; that date should be treated as reported detection timing rather than a fully documented public forensic timeline. Workday disclosed the incident during August 2025.

#1 Best Overall
Office Suite 2026 Special Edition for Windows 11-10-8-7-Vista-XP | PC Software and 1.000 New Fonts | Alternative to Microsoft Office | Compatible with Word, Excel and PowerPoint
  • THE ALTERNATIVE: The Office Suite Package is the perfect alternative to MS Office. It offers you word processing as well as spreadsheet analysis and the creation of presentations.
  • LOTS OF EXTRAS:✓ 1,000 different fonts available to individually style your text documents and ✓ 20,000 clipart images
  • EASY TO USE: The highly user-friendly interface will guarantee that you get off to a great start | Simply insert the included CD into your CD/DVD drive and install the Office program.
  • ONE PROGRAM FOR EVERYTHING: Office Suite is the perfect computer accessory, offering a wide range of uses for university, work and school. ✓ Drawing program ✓ Database ✓ Formula editor ✓ Spreadsheet analysis ✓ Presentations
  • FULL COMPATIBILITY: ✓ Compatible with Microsoft Office Word, Excel and PowerPoint ✓ Suitable for Windows 11, 10, 8, 7, Vista and XP (32 and 64-bit versions) ✓ Fast and easy installation ✓ Easy to navigate

Most importantly for customers, Workday said there was no indication that attackers accessed customer tenants or the data stored inside them. The available evidence therefore supports a limited compromise of a business system used by Workday—not a confirmed breach of Workday’s production environments or every customer’s HR platform.

Workday’s customer notice says the company does not call customers to request passwords or other secure information.

What information was accessed?

Confirmed or stated Not publicly established
Names Payroll data
Email addresses Benefits or employee records
Phone numbers Workday customer-tenant data
Commonly available business contact information Credentials, MFA secrets or API tokens
Access to a third-party CRM used by Workday The number of affected records or whether all accessed data was exfiltrated

“Accessed” should not automatically be read as “every record was copied.” The public disclosures do not establish the full scope of data viewed or taken, nor do they say that sensitive HR, payroll, financial or employee-record information was exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Similarly, references to Workday’s broad customer community—sometimes reported as roughly 70 million users—must not be mistaken for a confirmed victim count. No such number was established for this incident.

How the attack worked: vishing, not a demonstrated software exploit

Vishing is voice phishing: an attacker uses a phone call, often supported by text messages, to impersonate a trusted person and manipulate a target into revealing information or granting access.

In Workday’s account, attackers posed as HR or IT personnel. The company has not publicly described the exact technical sequence after the social-engineering contact. It has not, in the available notice, attributed the incident to a particular malware family, a Workday software vulnerability, a specific OAuth authorization, or a particular data-export tool.

That distinction matters. Phone-based impersonation can defeat otherwise strong cloud controls when employees or help-desk staff approve password resets, MFA changes, new-device enrollment or access requests based on a convincing conversation. Caller ID, internal terminology and urgency are not reliable proof of identity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the Salesforce attacks are being mentioned

The suspected connection is based on similarities in method and timing, not a public confirmation that Workday and Salesforce were breached by the same group.

Rank #3
MySoftware Company, Mysoftware My Database
  • Pre-designed templates for both business and personal use
  • 10,000 clipart images and 100 fonts
  • Notes table for history and to-do items
  • Sort, filter and index
  • Calculation & totaling

Google Threat Intelligence described a contemporaneous Salesforce-focused campaign in which attackers impersonated IT support and persuaded victims to authorize malicious or modified connected applications. Some activity involved tools resembling Salesforce Data Loader. Google said the campaign did not exploit a vulnerability inherent in Salesforce; it manipulated users and SaaS access workflows instead.

Workday’s incident had several similarities:

  • Phone-based impersonation of IT or support personnel
  • Social engineering rather than a publicly demonstrated vendor software exploit
  • Targeting of valuable SaaS or CRM information
  • Potential use of business contact data to support additional phishing

But the precise Workday attack chain is not public. It would be inaccurate to say that Salesforce was the affected Workday CRM, that Workday suffered a Salesforce breach, or that the same technical process was proven in both cases.

Google’s analysis is available in “The Cost of a Call.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was ShinyHunters responsible?

There is no confirmed public attribution by Workday. The ShinyHunters connection was suspected by outside observers because the incident resembled Salesforce-related intrusions and later extortion activity associated with the ShinyHunters name.

The labels require care:

  • ShinyHunters is a criminal brand used in extortion communications and data-leak claims.
  • UNC6040 is Google Threat Intelligence’s designation for a financially motivated cluster observed using vishing to compromise Salesforce environments.
  • UNC6240 refers to a cluster Google associated with later extortion activity following some intrusions and with actors claiming the ShinyHunters identity.

These labels do not necessarily describe one unified organization. Google has cautioned that apparent overlaps can reflect associated actors, criminal partnerships, shared infrastructure, impersonation or common tactics.

A January 2026 Google/Mandiant report described an expansion of ShinyHunters-branded SaaS data theft involving additional tracked clusters, including UNC6661, UNC6671 and UNC6240. That later activity provides context for the broader threat, but it does not prove that any of those clusters caused the 2025 Workday incident. See Google’s 2026 report.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Workday customers should do now

Even without evidence that customer tenants were accessed, the incident is relevant because exposed contact information can make later fraud more convincing. Workday customers should treat it as an identity and phishing-risk event.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Warn staff about impersonation. Tell employees that unsolicited calls or texts claiming to be from Workday, HR, payroll, IT or customer support should be treated as suspicious.
  2. Never disclose secrets by phone. Employees should not provide passwords, MFA codes, recovery codes, API tokens or security answers to a caller.
  3. Verify independently. End the call and use a known, independently retrieved support or internal contact channel. Do not rely on a number supplied by the caller or in the same message.
  4. Strengthen account recovery. Require dual approval or out-of-band confirmation for password resets, MFA changes, recovery-detail changes, new-device enrollment and privileged-account recovery.
  5. Review identity activity. Check identity-provider, help-desk and Workday administrative logs for unusual successful sessions, new authenticators, changed recovery details, newly created users and privilege changes.
  6. Audit connected applications. Review OAuth grants, integrations, service accounts and unusual data exports. Remove unused or unapproved connections.
  7. Use phishing-resistant MFA. Prioritize FIDO2/WebAuthn security keys or passkeys for administrators, help-desk personnel and other high-value users. Google and Mandiant have emphasized that stronger authentication must be paired with secure recovery procedures.
  8. Independently verify payroll changes. Require a separate confirmation before changing employee bank details, payment instructions or other financially sensitive records.

Security keys from vendors such as Yubico and authentication controls from providers such as Okta or Microsoft Entra ID may support this strategy, but no product replaces callback verification, least privilege and disciplined recovery workflows.

Why the incident matters beyond Workday

The exposed information may have been commonly available business contact data, but that does not make it harmless. A name, phone number, job title or corporate email address can help an attacker sound legitimate, identify administrators and construct a targeted pretext.

The larger lesson is that third-party systems around a SaaS platform can be valuable even when the core tenant remains isolated. CRM records, help-desk systems, identity providers, support portals and integration consoles may contain the reconnaissance needed to attack a more sensitive account later.

Organizations also commonly monitor failed logins while overlooking successful but unusual activity: a new authenticator, a recovery change, an unexpected OAuth grant or a bulk export performed after a convincing support call.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline

  • June 4, 2025: Google published research on UNC6040’s Salesforce-focused vishing activity.
  • August 5, 2025: Google said one of its Salesforce instances was affected by similar activity and that retrieved data was limited to basic business information.
  • August 6, 2025: Contemporary reporting identified this as Workday’s detection date.
  • August 2025: Workday published its customer-facing notice about the third-party CRM incident.
  • January 30, 2026: Google/Mandiant reported an expansion of ShinyHunters-branded SaaS data-theft operations involving multiple tracked clusters.

What remains unknown

  • The identity of the CRM vendor
  • The number of affected records
  • Whether attackers copied all or only some accessed information
  • Whether credentials or authentication information were exposed
  • The identities or number of affected employees
  • Whether regulators or law enforcement were notified
  • Whether the attackers attempted extortion
  • Whether any customer was separately targeted using the exposed contact information

Those gaps are why the most accurate description is a limited third-party CRM compromise caused by social engineering. It is not evidence, based on the cited disclosures, that Workday’s customer tenants were breached, that payroll records were exposed, or that ShinyHunters definitely conducted the attack.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.