惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Blog — PlanetScale
Blog — PlanetScale
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
I
InfoQ
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
L
LangChain Blog
F
Fortinet All Blogs
C
Check Point Blog
Google DeepMind News
Google DeepMind News
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Help Net Security
J
Java Code Geeks
月光博客
月光博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
IT之家
IT之家
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
宝玉的分享
宝玉的分享
Jina AI
Jina AI

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO
Workday confirms CRM breach via social engineering
Carly Page Carly Page · 2025-08-18 · via The Register - Security: CSO

CSO

Workday warns of CRM breach after social engineers make off with business contact details

HR SaaS giant insists core systems untouched

Workday has admitted that attackers gained access to one of its third-party CRM platforms, but insists its core systems and customer tenants are untouched.

In a short blog posted late last week, Workday disclosed that crooks sweet-talked staff by posing as HR or IT, and in doing so waltzed off with "some information" from an unnamed CRM system.

The company stressed there was "no indication" anyone had obtained customer data stored inside Workday's flagship SaaS apps.

"We acted quickly to cut the access and have added extra safeguards to protect against similar incidents in the future," Workday said, while failing to mention how long the attackers had access or what exact measures were taken to avoid such future incidents.

The biz hasn't said which CRM platform was targeted either, but said the attackers' loot appears to be limited to "primarily commonly available business contact information, like names, email addresses, and phone numbers" – the sort of stuff that can grease the wheels of future phishing or vishing scams.

Workday spokesperson Kirin May told The Register: "We're one of several companies targeted by a sophisticated social engineering scam. All signs show that our customers' Workday data remains secure. Some commonly available business contact information was accessed, and we've informed our customers and partners so they can protect themselves from similar campaigns. We've also adopted additional security measures internally to protect our own employees."

While Workday avoided naming names, infosec watchers have already linked the intrusion to ShinyHunters, the crew blamed for a string of Salesforce-related heists in recent weeks. The group's playbook is heavy on social engineering: calling staff while posing as IT or HR, then slipping in malicious OAuth apps to quietly drain cloud systems. Victims are said to include Adidas, Qantas, Dior, Tiffany & Co, Chanel, Cisco, Google, and Allianz Life, among others.

The timing certainly lines up. According to Bleeping Computer, Workday discovered the compromise almost two weeks ago, on August 6. It's since "notified affected customers," though the company didn't respond to The Register's questions about how many were caught up in the breach. 

For ShinyHunters, the Workday caper would be just the latest notch on the belt. The gang has made a name for itself flogging stolen data on underground forums and running brazen extortion schemes.

Over the weekend, it emerged that the group has been chumming up with some equally notorious names. As El Reg reported, ShinyHunters, Scattered Spider, and Lapsus$ appear to be swapping tips – and perhaps targets – in a shared Telegram hangout. Cybercrime cartels, it seems, are back in fashion. ®