Desk live·
ForensicPost
Cloud/Analysis/File 25-0815b

Workday Says Core Platform and Customer Tenants Were Not Affected

Workday stated that its core platform and customer tenants were not affected, and that no payroll data, national identifiers or HR records were exposed. The corpus should record what worked.

Constructed geometry · not a chart of case data
TargetWorkday
ActorShinyHunters
S. Rosler11 min readConfidence: medium2 sources reviewed

Workday stated that the incident at 25-0806b did not affect its core platform or customer tenants, and that the compromised material was primarily business contact information — names, email addresses and telephone numbers — rather than payroll data, national identifiers or HR records held within its product.

Consider What The Alternative Would Have Been

Workday holds payroll, employment terms, performance records, national identifiers and bank details for the workforces of a very large number of organisations.

A compromise reaching the product tenants would have been the largest workforce exposure in this database by a wide margin — the concentration structure at 25-0814 and 25-0801, applied to employment data that 25-0704 established has no public register anywhere.

What was actually taken was a sales contact list.

The Corpus Is Biased Against Recording This

This desk filed at 25-0807 that a database assembled from disclosures records failures in detail and successes almost never, and at 25-0628 that a claim of operations being unaffected deserves to be taken seriously rather than read as spin.

The same applies here. A boundary between a company’s own corporate systems and its customers’ production tenants held under a live attack. That is the outcome every multi-tenant architecture is supposed to produce and this corpus rarely gets to observe.

With The Caution That It Is The Company’s Own Account

Graded medium for that reason. The corpus recorded at 25-0807 that containment claims made early are sometimes revised, and this desk has no independent confirmation.

What can be said is that the claim is specific and falsifiable in a way that "no evidence of misuse" is not — it names systems and data classes, and a subsequent tenant exposure would contradict it plainly.

This is an analysis file

Built on company disclosure and public reporting, listed below. The scope claim is the company’s own and is not independently established. Corrections: corrections@forensicpost.com.

Sources
  1. Workday data breach 2025: what was exposed and how it happenedSecurity.org
  2. Human resources firm Workday disclosed a data breachSecurity Affairs
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary