Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Workday

Workday Vendor Cyber Rating & Cyber Score

workday.com

Workday is a leading provider of enterprise cloud applications for finance and human resources, helping customers adapt and thrive in a changing world. Workday applications for financial management, human resources, planning, spend management, and analytics are built with artificial intelligence and machine learning at the core to help organizations around the world embrace the future of work. Workday is used by more than 10,000 organizations around the world and across industries – from medium-sized businesses to more than 50% of the Fortune 500.


Workday A.I CyberSecurity Scoring

Workday
Company Information
Website:http://www.workday.com
Employees number:26,861
Number of followers:1,323,784
NAICS:5112
Industry Type:Software Development
Homepage:workday.com
Workday Risk Score (AI oriented)
Between 650 and 699
logo
WorkdaySoftware Development
Updated:
04/05/2026
656/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Workday Global Score (TPRM)
xxxx
logo
WorkdaySoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Workday
WorkdayWeak
Current Score
656B (WEAK)
01000
3 incidents
-52 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
660Before Incident
MAY 2026
656Before Incident
APRIL 2026
653Before Incident
MARCH 2026
722Before Incident
Breach
20 Mar 2026Workday
Notion, Slack, Google, Zoom, Nikkei and Workday: Your work apps are quietly handing 19 data points to someone

Workplace Apps Collect Extensive User Data, Raising Privacy and Security Concerns

651After Incident
CRITICAL-71
WORNOTGOOZOONIKTIN1777868873
Workplace Apps Collect Extensive User Data, Raising Privacy and Security Concerns A recent study by Incogni, analyzing data from the Google Play Store as of March 20, 2026, reveals that ten widely used workplace apps including Gmail, Microsoft Teams, Zoom Workplace, Slack, and Notion collect an average of 19 data points per app, with some sharing sensitive information with third parties. These apps, cumulatively downloaded over 12.5 billion times, are integral to U.S. corporate operations but pose significant privacy and security risks. Data Collection and Sharing Practices Gmail leads in data harvesting, collecting 26 distinct data types, including approximate location, app interactions, and user IDs for advertising. Microsoft Teams and Zoom Workplace follow closely, with 25 and 23 data types, respectively both uniquely gathering precise location data. Six of the ten apps, including Slack, Notion, and Zoom Workplace, use collected data for marketing, with Slack, Todoist, and Notion specifically harvesting employee email addresses for this purpose. Notion stands out for its outbound data flow, sharing eight data types such as email addresses, names, and device IDs with third parties, including advertising partners. The app’s privacy policy permits tracking tools on user browsers, raising concerns over the exposure of sensitive workspace content like HR records and client data. Regulatory scrutiny has intensified, particularly after the EU’s Data Protection Board tightened GDPR requirements in December 2024 regarding personal data use in AI training, directly impacting Notion’s third-party model integrations. Security Vulnerabilities and Breach History Most apps in the study have a history of breaches. In January 2026, a 96-gigabyte database containing 149 million login credentials 48 million tied to Gmail was exposed, attributed to infostealer malware on user devices. Slack suffered a November 2025 breach where attackers used stolen credentials to access accounts of over 17,000 Nikkei employees, exposing names, emails, and chat histories. Trello, Zoom, and Microsoft products have also faced incidents, with Trello data appearing for sale in January 2024. Workday is the only app in the analysis without a user data deletion option, despite holding employment records and payroll details. In August 2025, the platform confirmed two breaches linked to its Salesforce CRM, where attackers obtained business contact information as part of a ShinyHunters social engineering campaign. BYOD Risks and Platform Disparities Many employees install these apps on personal devices, exposing contact details, financial data, and location information to advertising networks or corporate administrators. Slack, for example, lacks end-to-end encryption, allowing workspace owners to access direct messages and private channels. While the study focuses on Google Play data, Incogni notes that iOS disclosures may differ, though past comparisons suggest similar privacy practices across platforms. The findings highlight the trade-offs between workplace productivity and data exposure, with recurring breaches and extensive tracking underscoring the risks of integrating these tools into daily operations.
INCIDENT DETAILS -
TYPE
Data CollectionPrivacy ViolationData Breach
MOTIVATION
Data Harvesting for AdvertisingFinancial GainEspionage
IMPACT
Login CredentialsEmail AddressesNamesChat HistoriesEmployment RecordsPayroll DetailsDevice IDsLocation DataGmailMicrosoft TeamsZoom WorkplaceSlackNotionTrelloWorkdayOperational Impact: Exposure of sensitive workspace content and corporate dataBrand Reputation Impact: Increased regulatory scrutiny and loss of user trustGDPR ViolationsPotential FinesIdentity Theft Risk: High
DATA BREACH
Login CredentialsEmail AddressesNamesChat HistoriesEmployment RecordsPayroll DetailsDevice IDsLocation Data149 million (Gmail-related)17,000 (Slack)Sensitivity Of Data: HighData Exfiltration: YesData Encryption: Lacking in some cases (e.g., Slack)Email AddressesNamesEmployment RecordsPayroll Details
FEBRUARY 2026
773Before Incident
JANUARY 2026
778Before Incident
DECEMBER 2025
774Before Incident
NOVEMBER 2025
774Before Incident
OCTOBER 2025
773Before Incident
SEPTEMBER 2025
766Before Incident
Breach
25 Sep 2025Workday
Salesloft

AI-Powered Supply Chain Attack via Compromised Salesloft-Drift Integration (2025)

721After Incident
CRITICAL-45
SAL2862828092525
The attack on Salesloft began with the compromise of an internal GitHub repository, where attackers stole a high-privilege OAuth token granting access to its Drift cloud application. Exploiting Drift’s trusted integrations, the attackers pivoted to Salesforce instances of multiple high-profile customers—including Palo Alto Networks, Cloudflare, Zscaler, and Tenable—exfiltrating customer conversation data, contact details, and sensitive business information. The breach exposed a supply-chain vulnerability, where a single compromised AI-powered integration (Drift’s chatbot) enabled mass data theft across 700+ organizations, including cybersecurity leaders. The attackers also harvested OpenAI API credentials, demonstrating the cascading risks of interconnected AI ecosystems. While companies like Okta mitigated damage via IP allow-listing, others faced reputational harm, forensic costs, and erosion of customer trust. The incident highlighted critical gaps in third-party risk management, token security, and AI integration monitoring, with long-term implications for enterprise security postures.
INCIDENT DETAILS -
TYPE
Supply Chain AttackData BreachUnauthorized AccessAI Integration Exploitation
MOTIVATION
Data TheftEspionageFinancial Gain (Potential)Supply Chain Disruption
IMPACT
Customer Conversation DataContact InformationAuthentication Tokens (Including OpenAI API Credentials)Salesforce Instance DataSalesloft GitHub RepositoriesDrift Cloud ApplicationConnected Salesforce InstancesOpenAI API IntegrationsForensic InvestigationsCustomer Trust ErosionIntegration AuditsSecurity Control OverhaulsExpected (Not Quantified)Severe (Especially for Cybersecurity Firms)Loss of Customer TrustIncreased Scrutiny of AI Security PracticesPotential Regulatory FinesContractual Breach ClaimsLitigation RiskHigh (Due to PII in Conversation Data)Low (Not Explicitly Mentioned)
DATA BREACH
Customer Conversation LogsContact InformationAPI CredentialsSalesforce DataHigh (PII, Business Communications, Authentication Tokens)Confirmed (Systematic via Salesforce Integrations)Conversation LogsContact DatabasesAPI TokensPotentially Calendar/Email DataNamesEmail AddressesPotentially Phone NumbersBusiness Roles
AUGUST 2025
811Before Incident
Breach
16 Aug 2025Workday
Workday: Workday hit in wave of social engineering attacks

Workday Third-Party Cyberattack Linked to ShinyHunters

771After Incident
MEDIUM-40
WOR1768679649
Workday Hit by Third-Party Cyberattack Linked to ShinyHunters Workday, a leading HR platform provider, disclosed a cyberattack on 16–17 August after threat actors breached its systems via a third-party supplier. The incident appears tied to a broader wave of attacks likely orchestrated through Salesforce products linked to the ShinyHunters cybercrime group, though Workday did not confirm the specific threat actor or software involved. In a public notice, Workday revealed that attackers accessed limited data from its third-party CRM platform, primarily business contact information such as names, email addresses, and phone numbers. The company emphasized that no customer tenant data or internal systems were compromised. Immediate containment measures were taken, including revoking access and implementing additional safeguards. The breach stemmed from a social engineering campaign targeting multiple large organizations, with the stolen data potentially intended for further phishing scams. Workday clarified that it never requests passwords or sensitive details via phone, urging users to verify communications through official support channels. The incident underscores the growing risk of supply chain attacks, where cybercriminals exploit vulnerabilities in third-party vendors to infiltrate larger targets. While the full scope of the campaign remains under investigation, the attack aligns with recent tactics attributed to ShinyHunters, a group known for high-profile data breaches.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft for Phishing Scams
IMPACT
Data Compromised: Business contact information (names, email addresses, phone numbers)Systems Affected: Third-party CRM platform
DATA BREACH
Type Of Data Compromised: Business contact informationSensitivity Of Data: Low to moderate (names, email addresses, phone numbers)Personally Identifiable Information: Names, email addresses, phone numbers
JULY 2025
814Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Workday ?
?
What was Workday's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Workday's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Workday's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Workday's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Workday's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Workday's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Workday's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Workday's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Workday's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Workday's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Workday's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Workday's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Workday ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Workday's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?