
California-based human resources software company Workday said it suffered a significant data security incident after hackers gained access to a third-party vendor platform used to manage customer data.
Workday, headquartered in Pleasanton, California, is a leading cloud-based software provider specialising in enterprise solutions for human capital management (HCM) and financial management. Recognised as a pioneer in the Software-as-a-Service (SaaS) industry, Workday has played a key role in transforming how organisations manage their people and finances.
In a data security incident notice published on its website, Workday said that it recently suffered a data security incident. The human resource company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
According to the notice, the breach occurred when an unauthorised threat actor used social engineering techniques to gain access to a vendor platform used by the company to manage customer data.
A social engineering campaign involves threat actors contacting employees, often via text or phone, while impersonating representatives from departments like Human Resources or IT. The goal is to deceive employees into revealing personal information or granting access to their accounts.
“The type of information the actor obtained was primarily commonly available business contact information, like names, email addresses, and phone numbers, potentially to further their social engineering scams.
“There is no indication of access to customer tenants or the data within them,” Workday said.
In recent months, several companies have fallen victim to data breaches in which threat actors employed social engineering tactics to gain access to vendor platforms used for managing customer data. This appears to be part of a broader campaign targeting Salesforce CRM tools, where attackers impersonated IT support personnel over the phone to steal organisational data and issue extortion demands.
A similar incident involving Allianz Life occurred in July where hackers leaked a database stolen from Allianz Life, containing approximately 2.8 million records of individual customers and business partners. The data includes sensitive personal information such as names, addresses, phone numbers, birth dates, and Tax IDs, as well as professional details like licenses, company affiliations, product approvals, and marketing classifications.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543