Human resources giant Workday has disclosed a data breach after attackers gained access to a third-party customer relationship management (CRM) platform in a recent social engineering attack.

  • my_hat_stinks@programming.dev
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 months ago

    The article claims the client DBs weren’t directly accessed but some client data was compromised. My guess would be employee data is safe but billing/contact info leaked.

    “We recently identified that Workday had been targeted and threat actors were able to access some information from our third-party CRM platform. There is no indication of access to customer tenants or the data within them.”

    However, some business contact information was exposed in the incident, including customer data that could be used in subsequent attacks.