Workday discovered on 6 August 2025 that attackers posing as internal human resources and IT staff had placed telephone calls and sent SMS messages to its employees in order to obtain access to a third-party customer relationship management system. The company disclosed publicly on 15 August. Reporting attributes the activity to the cluster tracked as ShinyHunters, also designated UNC6040.
The Pretext Was The Company’s Own Product Category
Workday sells human resources software. The attackers impersonated human resources staff to its own employees.
That is not a coincidence worth dwelling on for its irony. It is a structural observation: an HR pretext works everywhere, because every organisation has an HR function, employees expect unscheduled contact from it, and the requests it makes — verify your details, log in here, approve this — are exactly the actions an attacker needs.
The corpus recorded IT impersonation at 25-0806 and 25-0518. HR is the second universal authority, and it carries something IT does not: employees are conditioned not to question it, because the topics are personal and the consequences of non-compliance are employment-related.
Calls And SMS Together
The combination matters. A message establishes a plausible context in writing; a call supplies the urgency and the human presence that makes a request feel legitimate.
This desk filed at 25-1022 that voice phishing engaged no technical control at any point across four sectors in 2025. Adding SMS does not change that — it adds a channel with no authentication and a strong presumption of legitimacy.
And The Target Was, Again, A Connected Application
The objective was CRM access, obtained by persuading employees to authorise malicious OAuth applications — the mechanism at 25-0806 and the consent model at 25-0311.
By August this was the third distinct sector reached by the same technique in 2025, per the sequence at 25-0702. Workday was not selected as an HR company. It was selected as an organisation with employees and a Salesforce tenant.
Compiled from company disclosure and public reporting, listed below. Attribution follows published research assessments and is recorded as such. Corrections: corrections@forensicpost.com.