Workday, one of the world’s leading providers of human resources technology, has confirmed a data breach in which hackers accessed personal information from a third-party customer relationship management database.
In a blog post published late Friday, the company said the attackers stole an undisclosed amount of data, primarily contact details such as names, email addresses, and phone numbers.
Workday stopped short of confirming whether customer-specific information was compromised, stating only that there is “no indication of access to customer tenants or the data within them.” These customer systems typically hold sensitive HR files and employee records.
The company warned that the stolen information could be exploited for social engineering schemes, where hackers deceive victims into handing over sensitive data or access.
According to its website, Workday serves over 11,000 corporate clients and at least 70 million users globally. The breach, first reported by Bleeping Computer, was discovered on August 6.
While Workday did not disclose which third-party platform was compromised, the incident follows a string of recent cyberattacks targeting Salesforce-hosted databases. Major companies including Google, Cisco, Qantas, and Pandora have all recently suffered data theft from their Salesforce systems.
Google has linked these breaches to ShinyHunters, a hacking group notorious for using voice phishing to gain unauthorized access to corporate cloud databases. Reports suggest the group may be preparing a data leak site to pressure victims into paying to prevent public exposure, mirroring tactics used by ransomware gangs.
When asked for further details—such as the number of individuals affected or whether the stolen data involved Workday’s employees or its clients—company spokesperson Connor Spielmaker declined to elaborate beyond the official blog post. Workday has also not confirmed whether it possesses the technical logs necessary to determine what data was exfiltrated.
Notably, the breach disclosure on Workday’s blog was found to contain a hidden “noindex” tag, preventing search engines from indexing the page and making it harder for the public to find. The reason behind this decision remains unclear.



