CSIDB logo
Incident

Cushman & Wakefield

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 01:46

Linked entities

Victim
Cushman & Wakefield
Threat actors
3 actors
Sources
1 source

Timeline

Occurred
May 2026
Discovered
Undetermined
Disclosed
May 2026
Resolved
Pending

Summary

Cushman & Wakefield suffered a cyberattack involving voice phishing by hacker groups ShinyHunters and Qilin, resulting in unauthorized access to clients’ personal data including names, dates of birth, Social Security numbers, driver’s license numbers and financial information. A proposed class action alleges the firm failed to protect this data, leading to identity theft, fraud and associated stress for affected individuals, while the company maintains the lawsuit is baseless and says the breach was limited in scope. Additionally, a former employee filed a separate class action claiming the firm inadequately monitored its employee 401(k) plan for climate‑related financial risks.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or before May 10, 2026, hacker groups identified as ShinyHunters and Qilin, a Russian‑speaking cybercrime gang, gained access to Cushman & Wakefield’s systems through a successful vishing attack. The attackers obtained names, dates of birth, social security numbers, driver’s license numbers and financial information belonging to current and former clients and tenants. The breach was disclosed in a federal complaint filed in the Southern District of New York. According to the complaint, the attackers threatened to release the stolen data unless the company contacted them, a message that read “Make the right decision, don’t be the next headline.” Cushman & Wakefield did not engage with the hacker group.

Michelle Milewski, a commercial tenant from Illinois, filed a proposed class action on the Friday preceding May 12, 2026, alleging that the firm failed to protect her personal information. The lawsuit states that after the breach Milewski experienced identity theft, including unauthorized attempts to open new credit cards in her name and to change her mailing address and debit‑card account information. She also reported receiving a surge of spam and scam emails, text messages and phone calls, which caused anxiety and sleep disruption. The complaint accuses Cushman & Wakefield of negligence and of failing to implement industry‑standard cybersecurity measures or to meet minimum security standards before and after the incident.

A spokesperson for Cushman & Wakefield told The Post that the company is aware of the litigation and considers the lawsuit baseless, describing the ShinyHunters incident as limited in scope and saying the firm is communicating with any clients who were impacted. The spokesperson confirmed that the company did not respond to the hackers’ demands. In addition, a former employee filed a separate class‑action suit in March 2026, claiming that Cushman & Wakefield failed to adequately monitor and protect its employee 401(k) plan from climate‑related financial risks.

Sources

Sources available to members: 1 source.

CSIDB