According to Workday's Security and Trust blog on 15 August 2025, threat actors contacted Workday employees by text or phone while pretending to be from human resources or IT. Their goal was to trick staff into giving up account access or personal information. Workday said the actors accessed some information from its third-party CRM platform, primarily commonly available business contact data such as names, email addresses, and phone numbers, and reported no indication of access to customer tenants or the data within them. Public reporting does not name a spoofed login page, AiTM kit, TAP, OAuth consent flow, threat-actor brand, or the CRM vendor.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get into Workday's third-party CRM?

Attackers reached Workday's third-party CRM after social engineering Workday employees over text or phone while impersonating HR or IT and tricking them into giving up account access or personal information. According to Workday's 15 August 2025 disclosure, that access was enough to retrieve some CRM information. Public reporting does not establish how the handoff worked at the factor level, and it does not name TAP, a spoofed page, AiTM, or a specific MFA method.

Did the Workday incident hit customer tenants?

No. Workday stated there is no indication of access to customer tenants or the data within them. The disclosed impact sat on a third-party CRM platform used by Workday, not on customer Workday environments.

What data did the actors obtain?

According to Workday, the information obtained was primarily commonly available business contact information like names, email addresses, and phone numbers, potentially to further social engineering scams. Public reporting does not establish an exact affected record count.

Is this the same class as helpdesk vishing or a fake-login coach?

Yes at the attack-class level, with an honesty gap on mechanics. Workday documented live text and phone coaching under an HR or IT persona aimed at account access or personal information. Public reporting does not name TAP, helpdesk password reset, a spoofed login, or AiTM for this incident. Coached recovery handoffs and coached fake logins still sit in the same social-engineering class: someone is talked into handing over a transferable factor or usable access outside a trustworthy channel. A fix for that class exists; the companion post covers prevention without replaying the incident narrative.

What did Workday say staff should expect from real IT or HR?

Workday stated it will never contact anyone by phone to request a password or any other secure details, and that official communications come only through trusted support channels. The company said it cut access and added extra safeguards after identifying it had been targeted. The same blog page lists adjacent reading on the Salesloft Drift security incident; Workday does not present that item as the same event.