ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Workday is a leading provider of enterprise cloud applications for finance and human resources, helping customers adapt and thrive in a changing world. Workday applications for financial management, human resources, planning, spend management, and analytics are built with artificial intelligence and machine learning at the core to help organizations around the world embrace the future of work. Workday is used by more than 10,000 organizations around the world and across industries – from medium-sized businesses to more than 50% of the Fortune 500.

Workday A.I CyberSecurity Scoring

Workday

Company Details

Linkedin ID:

workday

Employees number:

26,861

Number of followers:

1,323,784

NAICS:

5112

Industry Type:

Software Development

Homepage:

workday.com

IP Addresses:

Scan still pending

Company ID:

WOR_2352830

Scan Status:

In-progress

AI scoreWorkday Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/workday.jpeg
Workday Software Development
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreWorkday Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/workday.jpeg
Workday Software Development
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Workday

Fair
Current Score
775
Baa (Fair)
01000
1 incidents
-40.0 avg impact

Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.

JANUARY 2026
778
DECEMBER 2025
774
NOVEMBER 2025
774
OCTOBER 2025
773
SEPTEMBER 2025
774
AUGUST 2025
811
Breach
16 Aug 2025 • Workday: Workday hit in wave of social engineering attacks
Workday Third-Party Cyberattack Linked to ShinyHunters

**Workday Hit by Third-Party Cyberattack Linked to ShinyHunters** Workday, a leading HR platform provider, disclosed a cyberattack on **16–17 August** after threat actors breached its systems via a third-party supplier. The incident appears tied to a broader wave of attacks likely orchestrated through **Salesforce products** linked to the **ShinyHunters cybercrime group**, though Workday did not confirm the specific threat actor or software involved. In a public notice, Workday revealed that attackers accessed limited data from its **third-party CRM platform**, primarily **business contact information** such as names, email addresses, and phone numbers. The company emphasized that **no customer tenant data or internal systems** were compromised. Immediate containment measures were taken, including revoking access and implementing additional safeguards. The breach stemmed from a **social engineering campaign** targeting multiple large organizations, with the stolen data potentially intended for further phishing scams. Workday clarified that it **never requests passwords or sensitive details via phone**, urging users to verify communications through official support channels. The incident underscores the growing risk of **supply chain attacks**, where cybercriminals exploit vulnerabilities in third-party vendors to infiltrate larger targets. While the full scope of the campaign remains under investigation, the attack aligns with recent tactics attributed to **ShinyHunters**, a group known for high-profile data breaches.

771
medium -40
WOR1768679649
Data Breach
Third-Party Supplier Compromise
Social Engineering
Data Theft for Phishing Scams
Data Compromised: Business contact information (names, email addresses, phone numbers) Systems Affected: Third-party CRM platform
Containment Measures: Revoked access to the third-party CRM platform, implemented additional safeguards Communication Strategy: Public notice urging users to verify communications through official support channels
Type Of Data Compromised: Business contact information Sensitivity Of Data: Low to moderate (names, email addresses, phone numbers) Personally Identifiable Information: Names, email addresses, phone numbers
Growing risk of supply chain attacks via third-party vendors; importance of verifying communications through official channels
Enhance third-party vendor security assessments; educate users on phishing risks; implement multi-factor authentication for third-party access
Ongoing
Workday never requests passwords or sensitive details via phone
Urged users to verify communications through official support channels
Entry Point: Third-party CRM platform
Root Causes: Social engineering campaign targeting third-party supplier Corrective Actions: Revoked access, implemented additional safeguards
JULY 2025
814
JUNE 2025
814
MAY 2025
814
APRIL 2025
814
MARCH 2025
814
FEBRUARY 2025
814

Frequently Asked Questions

According to Rankiteo, the current A.I.-based Cyber Score for Workday is 775, which corresponds to a Fair rating.

According to Rankiteo, the A.I. Rankiteo Cyber Score for December 2025 was 774.

According to Rankiteo, the A.I. Rankiteo Cyber Score for November 2025 was 774.

According to Rankiteo, the A.I. Rankiteo Cyber Score for October 2025 was 773.

According to Rankiteo, the A.I. Rankiteo Cyber Score for September 2025 was 774.

According to Rankiteo, the A.I. Rankiteo Cyber Score for August 2025 was 811.

According to Rankiteo, the A.I. Rankiteo Cyber Score for July 2025 was 814.

According to Rankiteo, the A.I. Rankiteo Cyber Score for June 2025 was 814.

According to Rankiteo, the A.I. Rankiteo Cyber Score for May 2025 was 814.

According to Rankiteo, the A.I. Rankiteo Cyber Score for April 2025 was 814.

According to Rankiteo, the A.I. Rankiteo Cyber Score for March 2025 was 814.

According to Rankiteo, the A.I. Rankiteo Cyber Score for February 2025 was 814.

Over the past 12 months, the average per-incident point impact on Workday’s A.I Rankiteo Cyber Score has been -40.0 points.

You can access Workday’s cyber incident details on Rankiteo by visiting the following link: https://www.rankiteo.com/company/workday.

You can find the summary of the A.I Rankiteo Risk Scoring methodology on Rankiteo by visiting the following link: Rankiteo Algorithm.

You can view Workday’s profile page on Rankiteo by visiting the following link: https://www.rankiteo.com/company/workday.

With scores of 18.5/20 from OpenAI ChatGPT, 20/20 from Mistral AI, and 17/20 from Claude AI, the A.I. Rankiteo Risk Scoring methodology is validated as a market leader.