Source: BleepingComputer
Author: Sergiu Gatlan
URL: https://www.bleepingcomputer.com/news/security/hr-giant-workday-discloses-data-breach-amid-salesforce-attacks/
ONE SENTENCE SUMMARY:
Workday experienced a data breach after attackers accessed a third-party CRM platform via social engineering, exposing business contact information.
MAIN POINTS:
- Workday faced a data breach through a third-party CRM attack.
- The breach involved social engineering tactics targeting Workday and other large organizations.
- No customer tenants or sensitive data were accessed.
- Exposed information includes names, emails, and phone numbers.
- The breach occurred around August 6.
- Attackers impersonated HR or IT to trick employees.
- ShinyHunters extortion group is linked to these types of attacks.
- Multiple global companies, like Google and Adidas, were also targeted.
- ShinyHunters use OAuth apps to access Salesforce databases.
- Stolen data is used for extortion by the attackers.
TAKEAWAYS:
- Vigilance against social engineering is crucial for large organizations.
- Third-party platforms can be vulnerable points of entry.
- Regular monitoring and quick identification of breaches are essential.
- Employee training on phishing and impersonation threats is vital.
- Engaging with cybersecurity reports can help anticipate future threats.