---
title: Hackers Target Workday in Social Engineering Attack
metaTitle: "Hackers Target Workday with Social Engineering"
description: "A major player in human resources has fallen prey to the sort of human-oriented attack strategy that is increasingly common, effective, and dangerous."
slug: workday-social-engineering-attack
date: "2025-08-19T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/workday-social-engineering-attack.webp"
  alt: A cocker spaniel in Groucho glasses.
sourcePublisher:
  name: Cybersecurity Dive
  url: "https://www.cybersecuritydive.com/"
sourceArticle:
  url: "https://www.cybersecuritydive.com/news/hackers-target-workday-in-social-engineering-attack/758095/"
tags: [Impersonation, Social Engineering, Data Breach]
status: published
---

Workday has confirmed that it fell victim to a wide-ranging social engineering campaign that allowed hackers to access information at one of its third-party vendors.

The hackers work by impersonating IT and human-resources personnel in order to trick employees into sharing their personal information and account credentials, Workday said in a blog post published Friday.

Breaching the customer-support system gave the hackers access to support tickets that included Workday customers’ names, email addresses and phone numbers, which the hackers could use to conduct further social-engineering attacks. But Workday said there was no sign that the intruders had accessed data stored on its own servers...
