What happened
On August 19, 2025, Workday disclosed a security incident that started with the breach of a third-party customer relationship management (CRM) platform (reportedly Salesforce).
Workday's core systems and customer tenants were not affected. But attackers used social engineering and OAuth abuse to get into the CRM anyway, and that's the part worth paying attention to. I spend most of my time on OAuth and token-theft cases, and this is the SaaS supply-chain risk I keep warning teams about.
Incident at a glance
| Field | Details |
|---|---|
| Breach Discovered | August 6, 2025 |
| Public Disclosure | August 15, 2025 |
| Attack Type | Phishing (voice & text), Impersonation, OAuth exploitation |
| Impacted Systems | Third-party CRM (Salesforce reported) |
| Workday Systems | Core systems and tenants not impacted |
The phishing-to-OAuth chain
Here's how the attack moved, step by step:
- Initial Access – Workday staff hit with voice phishing (vishing) and SMS phishing (smishing) campaigns.
- Impersonation – Attackers posed as HR/IT staff to push employees toward malicious actions.
- Credential Harvesting – Victims were tricked into authorizing malicious OAuth apps.
- CRM Exploitation – Those OAuth integrations opened the door to the CRM platform.
- Data Exfiltration – Contact data (names, emails, phone numbers) was pulled for follow-on phishing and extortion.
The tradecraft matches the ShinyHunters campaign that's been hammering major CRM/SaaS platforms. The thing people miss about OAuth abuse is that it doesn't trip the usual alarms. There's no malware, no failed-login spike, no password to reset. A user clicks "Allow," and the token does the rest. We walked through that exact blind spot in our piece on OAuth token theft via device-code phishing.
What was exposed
The compromised data was business contact information:
- Names
- Email addresses
- Phone numbers
➡️ On its own, none of that looks alarming. But it's exactly the raw material for escalated phishing, impersonation, and social engineering down the line.
Who's behind it
| Attribute | Details |
|---|---|
| Suspected Group | ShinyHunters |
| Motivation | Data theft, resale, extortion |
| Techniques Used | Vishing, Smishing, Malicious OAuth integrations |
| Linked Campaigns | Adidas, Qantas, Allianz Life, Louis Vuitton, Dior, Chanel, Google |
| Historical Activity | Breaches at Snowflake, AT&T, PowerSchool |
| Threat Level | High – persistent SaaS/CRM targeting |
What this should change in your thinking
- Third-Party Weakness – Your own systems can be airtight and an integrated SaaS tool like a CRM still gets you.
- "Low-Risk" Data Value – Emails and phone numbers feed secondary phishing and impersonation campaigns.
- OAuth Exploitation – Malicious OAuth apps are a fast-growing SaaS attack vector, and most orgs barely monitor them.
- Supply-Chain Vigilance – Evaluate SaaS resilience with the same seriousness you give core systems.
We saw the same SaaS-integration pattern play out in the Anodot and Snowflake token-theft case and again in the Vietnam Airlines Salesforce breach.
What to do about it
Workday recommends a set of proactive measures for customers and partners:
1. Train your people
- Run phishing and vishing simulation training.
- Make reporting suspicious calls and SMS quick and routine.
2. Tighten authentication and access
- Enforce adaptive MFA across CRM/SaaS accounts.
- Apply least-privilege to CRM access.
- Regularly audit and revoke dormant accounts.
3. Govern OAuth
- Require formal approval before any third-party app integrates with your SaaS/CRMs.
- Continuously monitor for malicious or unverified OAuth apps.
4. Manage vendor and SaaS risk
- Run security assessments on SaaS providers.
- Confirm they're resilient to OAuth and social engineering.
- Limit what data lives in CRMs (data minimization).
5. Sharpen incident response
- Expand IR playbooks to cover OAuth-integrated app exploits and CRM-targeted phishing.
- Watch login and token usage for anomalies.
Closing thought
The Workday CRM breach is a clean example of how attackers go after supply-chain SaaS platforms, targeting OAuth integrations and CRM logins through phishing.
Workday's main systems weren't breached. Yet the exposed contact data sets up large-scale impersonation and phishing that could end up doing more damage over time than the original incident.
The takeaway: harden SaaS integrations, govern OAuth apps strictly, and train people against phishing and vishing. Your SaaS dependencies deserve the same monitoring and response rigor as your core stack. One practical layer is planting decoy OAuth tokens and credentials that page you the instant they're touched — see how Mine2's deception platform turns a malicious app authorization into an immediate alert.
Neha
Cloud Security Architect, Mine2
Neha works on cloud and identity security at Mine2, covering SaaS, OAuth, and the credential-theft paths attackers favour in the cloud.
Recent Articles
One Token, Dozens of Victims: How the Anodot SaaS Integration Breach Rewrites the Third-Party Risk Playbook
100 Million Downloads, One Poisoned Package: How the Axios npm Attack Proves Developer Credentials Are the New Crown Jewels
React2Shell CVE-2025-55182: 766 Next.js Hosts Breached in Automated Credential-Theft Wave
Need Security Help?
Protect your organization with MINE2's cyber deception platform.
