the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Workday Data Breach Hits 70M Users Amid Salesforce Attack Wave

ArticlesNewsletters
ArticlesNewsletters
Security

Workday Data Breach Hits 70M Users Amid Salesforce Attack Wave

HR giant confirms hackers stole personal data from customer database serving 70M users

by The Tech Buzz

PUBLISHED: Mon, Aug 18, 2025, 1:39 PM UTC | UPDATED: Fri, Sep 4, 2026, 3:29 AM UTC

Add as a preferred source on Google
Workday Data Breach Hits 70M Users Amid Salesforce Attack Wave

Workday, the HR software giant serving 70 million users worldwide, just confirmed hackers breached one of its third-party customer databases and made off with personal information including names, emails, and phone numbers. The breach, discovered August 6, follows a coordinated wave of attacks targeting Salesforce-hosted databases that has hit Google, Cisco, and other major enterprises in recent weeks.

Workday just became the latest casualty in what security experts are calling a coordinated assault on enterprise cloud databases. The HR technology giant confirmed hackers penetrated one of its third-party customer relationship databases, stealing an undisclosed amount of personal information that could affect its 70 million users across 11,000+ corporate customers worldwide.

The timing couldn't be worse for enterprise security teams. According to Bleeping Computer's reporting, Workday discovered the breach on August 6 – right in the middle of an unprecedented wave of attacks targeting Salesforce-hosted customer databases. In recent weeks, Google, Cisco, Qantas, and retailer Pandora have all reported similar breaches affecting their cloud-based customer data stores.

What makes this breach particularly concerning is Workday's careful wording around customer impact. In a blog post published late Friday, the company stated there was "no indication of access to customer tenants or the data within them" – but notably didn't rule out that customer information was compromised. Those customer tenants typically house the bulk of HR files and sensitive employee data that make Workday such a attractive target for cybercriminals.

Advertisement

Google has already attributed the broader attack campaign to ShinyHunters, a notorious hacking group that specializes in voice phishing attacks. The group's modus operandi involves tricking company employees into granting access to cloud databases, then preparing data leak sites to extort victims – essentially operating like a ransomware gang without the encryption. "ShinyHunters was likely in the process of preparing a data leak site to extort its victims into paying the hackers to delete the data," Google reported earlier this month.

The stolen data from Workday's breach includes names, email addresses, and phone numbers – exactly the kind of information that fuels sophisticated social engineering campaigns. "The stolen information may be used to further social engineering scams, where hackers trick or threaten victims into giving them access to sensitive data," the company warned in its disclosure.

But here's where the story takes an odd turn. Workday appears to be actively hiding its breach disclosure from public view. The company's blog post contains a hidden "noindex" tag in its source code, which instructs search engines like Google to ignore the page entirely. This makes it nearly impossible for anyone searching the web to discover the breach notification – a highly unusual move that raises questions about corporate transparency during security incidents.

Workday representatives haven't responded to questions about the scope of the breach, including how many individuals were affected or whether the stolen data belongs to Workday employees or their corporate customers' HR databases. The company also hasn't identified which third-party platform was breached, though the timing strongly suggests it's connected to the ongoing Salesforce database attacks.

Advertisement

For enterprise security teams, this represents a nightmare scenario. Workday processes some of the most sensitive employee data in corporate America – everything from Social Security numbers to salary information and performance reviews. While the company insists core customer systems weren't accessed, the breach of contact databases creates a perfect launching pad for targeted attacks against Workday's extensive customer base.

The broader implications extend far beyond Workday. The coordinated nature of these Salesforce database attacks suggests cybercriminals have identified systematic vulnerabilities in how enterprises configure and secure their cloud-based customer relationship management systems. With ShinyHunters apparently targeting the largest technology companies first, smaller enterprises using similar configurations should be scrambling to audit their own database security protocols.

The Workday breach exposes how quickly a coordinated cyber campaign can cascade across enterprise software ecosystems. With 70 million users potentially affected and the company's unusual decision to hide its disclosure from search engines, this incident highlights both the growing sophistication of social engineering attacks and concerning gaps in corporate transparency. As ShinyHunters continues targeting Salesforce-hosted databases, enterprise security teams face an urgent imperative to audit their cloud configurations before becoming the next victim in this expanding campaign.

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

More in Security

ClarityCheck Exposes 9M+ Facial Images in Database Breach

ClarityCheck Exposes 9M+ Facial Images in Database Breach

Apple spyware alerts hit 'unprecedented' number of users

Apple spyware alerts hit 'unprecedented' number of users

Military Apps Expose US Troops to Foreign Code From China, Russia

Military Apps Expose US Troops to Foreign Code From China, Russia

Russia Used Cellebrite Tools After Promised Cutoff

Russia Used Cellebrite Tools After Promised Cutoff

Spotify Exploited: Fake Podcasts Boost Illegal Drug Sites

Spotify Exploited: Fake Podcasts Boost Illegal Drug Sites

7-Eleven data breach affects over 185,000 people’s personal data

7-Eleven data breach affects over 185,000 people’s personal data

More Articles

These special phone and app features can help protect you from spyware

These special phone and app features can help protect you from spyware

May 23

Adobe patches PDF zero-day exploited since November

Adobe patches PDF zero-day exploited since November

Apr 14

Hack-for-hire group exposed targeting Android and iCloud users

Hack-for-hire group exposed targeting Android and iCloud users

Apr 8

Money Transfer App Duc Exposes Thousands of IDs on Open Server

Money Transfer App Duc Exposes Thousands of IDs on Open Server

Apr 2

WhatsApp Alerts 200 Users Hit by Italian Government Spyware

WhatsApp Alerts 200 Users Hit by Italian Government Spyware

Apr 1

Iranian Hackers Breach FBI Director Kash Patel's Gmail Account

Iranian Hackers Breach FBI Director Kash Patel's Gmail Account

Mar 27