Workday , a leading provider of cloud applications for businesses in the finance and human resources sectors , was targeted by a sophisticated social engineering campaign that led to a data breach (via a third-party Customer Relationship Management – CRM) platform.

Workday data breach
The incident did not impact customer or tenant data. According to Workday, threat actors are targeting many large companies through sophisticated social engineering schemes. These attacks involve communicating with employees via text messages or phone calls. The attackers say they are part of the HR and IT departments.
See also: IBM: Cost of data breach in the US is rising
The main goal of the attackers is to trick employees into handing over account credentials or other sensitive personal information. Workday’s security team has identified that the company was also targeted by hackers, resulting in unauthorized access to certain information within its third-party CRM system. According to the statement , the compromised data was primarily “business contact information, such as names, email addresses, and phone numbers.”
The compromised data may seem non-critical, but in practice it is valuable raw material for targeted phishing and vishing campaigns. With this information, attackers can create more convincing scenarios.

Indeed, it is believed that threat actors obtained this information to fuel further social engineering scams. The company confirms that its core systems and customer environments remain secure: “There is no indication of access to customer tenants or the data within them.”
See also: CISA and FBI warn of increased Interlock ransomware attacks
After detecting the data breach, Workday's cybersecurity team acted immediately to terminate unauthorized access and has since implemented additional security measures to prevent similar incidents.
The company is using this event to raise security awareness among its employees and the public. As a reminder to its users and the general public, Workday reiterated its communication policies , stating: “ Workday will never contact anyone over the phone to ask for a password or other details. All official communications from Workday come through trusted support channels .”
This incident highlights a growing trend where cybercriminals are exploiting the human element to infiltrate corporate networks. The human element remains the weak link. Even with the best firewalls and security systems, a duped employee can open a “back door” and allow hackers into the systems.
See also: Allianz Life: Data breach affects customers
At the same time, by targeting third-party vendors and using deceptive social engineering tactics, attackers can bypass traditional defenses. For more details on Workday's security protocols, the company directs customers to the official Security and Trust website.

Protection
For Organizations
- Education & Awareness
- Regular seminars on identifying social engineering attacks (phishing, vishing, smishing).
- Simulated phishing campaigns to identify weak points.
- Communication Policies
- Clear instructions: no company requests credentials via email/SMS/phone.
- Internal channels for immediate reporting of suspicious messages or calls.
- Strong Access Control
- Mandatory use of Multi-Factor Authentication (MFA).
- Least privilege access for employees and partners.
- Third Party Provider Audit
- Systematic vendor risk management with security assessment.
- Contracts with security clauses and periodic audits.
- Technical Defense Measures
- Detection of login anomalies (e.g. logins from unknown locations).
- Anti-phishing filters, email authentication (SPF, DKIM, DMARC).
- SIEM & SOC for continuous monitoring of suspicious behaviors.
- Incident Response Plan
- Breach response plan with clear roles.
- Simulations (tabletop exercises) to improve preparedness.
For Users / Employees
- Verify communication – never reveal passwords in calls/emails. If in doubt, call back the company's official number.
- Strong, unique passwords – use a password manager to avoid reuse.
- MFA on all critical accounts – even if a password is stolen, it remains useless.
- Skepticism of urgent requests – time pressure is a common ploy of attackers.
- Regular account audits – monitoring for suspicious activity and quick reporting to the IT team.
Source: cybersecuritynews
