ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Workday Reports Major Data Breach After Hackers Access Third-Party Vendor Platform

California-based human resources software company Workday said it suffered a significant data security incident after hackers gained access to a third-party vendor platform used to manage customer data.

 

Workday, headquartered in Pleasanton, California, is a leading cloud-based software provider specialising in enterprise solutions for human capital management (HCM) and financial management. Recognised as a pioneer in the Software-as-a-Service (SaaS) industry, Workday has played a key role in transforming how organisations manage their people and finances.

 

In a data security incident notice published on its website, Workday said that it recently suffered a data security incident. The human resource company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. 

 

According to the notice, the breach occurred when an unauthorised threat actor used social engineering techniques to gain access to a vendor platform used by the company to manage customer data.

 

A social engineering campaign involves threat actors contacting employees, often via text or phone, while impersonating representatives from departments like Human Resources or IT. The goal is to deceive employees into revealing personal information or granting access to their accounts.

 

“The type of information the actor obtained was primarily commonly available business contact information, like names, email addresses, and phone numbers, potentially to further their social engineering scams.

 

“There is no indication of access to customer tenants or the data within them,” Workday said.

 

In recent months, several companies have fallen victim to data breaches in which threat actors employed social engineering tactics to gain access to vendor platforms used for managing customer data. This appears to be part of a broader campaign targeting Salesforce CRM tools, where attackers impersonated IT support personnel over the phone to steal organisational data and issue extortion demands.

 

A similar incident involving Allianz Life occurred in July where hackers leaked a database stolen from Allianz Life, containing approximately 2.8 million records of individual customers and business partners. The data includes sensitive personal information such as names, addresses, phone numbers, birth dates, and Tax IDs, as well as professional details like licenses, company affiliations, product approvals, and marketing classifications.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543