Desk live·
ForensicPost
Cloud/Identity/File 25-0806b

Attackers Posing as HR and IT Staff Phoned Workday Employees

Workday discovered on 6 August 2025 that attackers posing as internal HR and IT staff had called and messaged its employees to obtain access to a third-party CRM.

Constructed geometry · not a chart of case data
TargetWorkday
ActorShinyHunters
D. Kennedy12 min readConfidence: high3 sources reviewed

Workday discovered on 6 August 2025 that attackers posing as internal human resources and IT staff had placed telephone calls and sent SMS messages to its employees in order to obtain access to a third-party customer relationship management system. The company disclosed publicly on 15 August. Reporting attributes the activity to the cluster tracked as ShinyHunters, also designated UNC6040.

The Pretext Was The Company’s Own Product Category

Workday sells human resources software. The attackers impersonated human resources staff to its own employees.

That is not a coincidence worth dwelling on for its irony. It is a structural observation: an HR pretext works everywhere, because every organisation has an HR function, employees expect unscheduled contact from it, and the requests it makes — verify your details, log in here, approve this — are exactly the actions an attacker needs.

The corpus recorded IT impersonation at 25-0806 and 25-0518. HR is the second universal authority, and it carries something IT does not: employees are conditioned not to question it, because the topics are personal and the consequences of non-compliance are employment-related.

Calls And SMS Together

The combination matters. A message establishes a plausible context in writing; a call supplies the urgency and the human presence that makes a request feel legitimate.

This desk filed at 25-1022 that voice phishing engaged no technical control at any point across four sectors in 2025. Adding SMS does not change that — it adds a channel with no authentication and a strong presumption of legitimacy.

And The Target Was, Again, A Connected Application

The objective was CRM access, obtained by persuading employees to authorise malicious OAuth applications — the mechanism at 25-0806 and the consent model at 25-0311.

By August this was the third distinct sector reached by the same technique in 2025, per the sequence at 25-0702. Workday was not selected as an HR company. It was selected as an organisation with employees and a Salesforce tenant.

How we reported this

Compiled from company disclosure and public reporting, listed below. Attribution follows published research assessments and is recorded as such. Corrections: corrections@forensicpost.com.

Sources
  1. Human resources firm Workday disclosed a data breachSecurity Affairs
  2. Workday discloses data breach following CRM-targeted social engineering attackIT Security Guru
  3. Flash report: Workday breach linked to social engineering attackZeroFox
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary