惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
博客园 - 【当耐特】
GbyAI
GbyAI
M
MIT News - Artificial intelligence
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans
罗磊的独立博客
Apple Machine Learning Research
Apple Machine Learning Research
腾讯CDC
F
Fortinet All Blogs
IT之家
IT之家
WordPress大学
WordPress大学
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
DataBreaches.Net
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Help Net Security
V
Visual Studio Blog
小众软件
小众软件
Y
Y Combinator Blog

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO
Workday confirms CRM breach via social engineering
Carly Page Carly Page · 2025-08-18 · via The Register - Security: CSO

CSO

Workday warns of CRM breach after social engineers make off with business contact details

HR SaaS giant insists core systems untouched

Workday has admitted that attackers gained access to one of its third-party CRM platforms, but insists its core systems and customer tenants are untouched.

In a short blog posted late last week, Workday disclosed that crooks sweet-talked staff by posing as HR or IT, and in doing so waltzed off with "some information" from an unnamed CRM system.

The company stressed there was "no indication" anyone had obtained customer data stored inside Workday's flagship SaaS apps.

"We acted quickly to cut the access and have added extra safeguards to protect against similar incidents in the future," Workday said, while failing to mention how long the attackers had access or what exact measures were taken to avoid such future incidents.

The biz hasn't said which CRM platform was targeted either, but said the attackers' loot appears to be limited to "primarily commonly available business contact information, like names, email addresses, and phone numbers" – the sort of stuff that can grease the wheels of future phishing or vishing scams.

Workday spokesperson Kirin May told The Register: "We're one of several companies targeted by a sophisticated social engineering scam. All signs show that our customers' Workday data remains secure. Some commonly available business contact information was accessed, and we've informed our customers and partners so they can protect themselves from similar campaigns. We've also adopted additional security measures internally to protect our own employees."

While Workday avoided naming names, infosec watchers have already linked the intrusion to ShinyHunters, the crew blamed for a string of Salesforce-related heists in recent weeks. The group's playbook is heavy on social engineering: calling staff while posing as IT or HR, then slipping in malicious OAuth apps to quietly drain cloud systems. Victims are said to include Adidas, Qantas, Dior, Tiffany & Co, Chanel, Cisco, Google, and Allianz Life, among others.

The timing certainly lines up. According to Bleeping Computer, Workday discovered the compromise almost two weeks ago, on August 6. It's since "notified affected customers," though the company didn't respond to The Register's questions about how many were caught up in the breach. 

For ShinyHunters, the Workday caper would be just the latest notch on the belt. The gang has made a name for itself flogging stolen data on underground forums and running brazen extortion schemes.

Over the weekend, it emerged that the group has been chumming up with some equally notorious names. As El Reg reported, ShinyHunters, Scattered Spider, and Lapsus$ appear to be swapping tips – and perhaps targets – in a shared Telegram hangout. Cybercrime cartels, it seems, are back in fashion. ®