Workday Confirms Data Breach Exposing Customer Data and Case Information

Workday has confirmed that a recent compromise of Salesloft’s Drift application resulted in unauthorized access to customer-facing data and basic case information within its Salesforce environment.

In response to the incident, Workday took immediate containment measures, engaged an independent forensic firm, and is collaborating closely with affected customers to minimize risks.

Incident Discovery and Initial Response

Workday’s security team detected anomalous activity originating from the Drift integration with Salesforce, a third-party application provided by Salesloft.

Within hours of discovery, Workday disabled the Drift connector, revoked all associated OAuth tokens, and began systematically removing residual integrations.

Concurrently, a top-tier digital forensics firm was retained to conduct a comprehensive investigation of Workday’s systems and downstream vendor implementations of Drift.

Salesloft’s public update on August 26 confirmed that a sophisticated threat actor had obtained Drift’s OAuth credentials and leveraged them to perform targeted search queries in customer Salesforce instances.

Workday’s subsequent internal review verified that this activity did indeed traverse its Salesforce tenant, prompting immediate outreach to customers who may have shared credentials via support cases.

Scope of Data Exposure

The forensic analysis determined that the threat actor’s queries returned a limited subset of non-sensitive metadata.

Specifically, exposed fields included business contact details, support case identifiers, tenant attributes such as name and data center location, product and service listings, training course enrollments with certificates, and associated event logs.

Crucially, the adversary did not access file attachments, contracts, order forms, or any documents submitted through Salesforce cases.

While standard best practices discourage inclusion of passwords or sensitive credentials in case notes, Workday has launched a full audit of all historical case text to identify any inadvertent disclosures.

Customers will receive direct notifications should any unique credentials or secret tokens be detected.

Workday emphasizes that no direct tenant compromise occurred through its own platform, and the attacker’s reach was constrained to the Salesforce layer managed by Drift.

Workday strongly advises customers to rotate any credentials transmitted via Salesforce cases.

Organizations should enforce robust multi-factor authentication across all user accounts and implement step-up authentication for high-privilege operations.

Additionally, customers are encouraged to conduct regular phishing awareness training, simulate phishing assessments, and monitor user activity logs for unusual behavior.

Detailed configuration instructions for multi-factor and step-up authentication are available in Workday’s administrative documentation.

For customers with direct Drift relationships, Workday recommends independent verification of impact based on their individual integration configurations.

Salesloft has also published supplemental guidance and security recommendations on its trust portal to assist in fortifying the Drift ecosystem.

Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories