Cushman & Wakefield, one of the world’s largest commercial real estate services companies, confirmed in May 2026 that threat actors stole and publicly leaked data belonging to over 310,000 individuals, exposing sensitive business contact records in a brazen “pay or leak” campaign.
The breach was orchestrated by ShinyHunters, a prolific cybercriminal group with a long track record of targeting large enterprises.
The attackers reportedly used a vishing (voice phishing) technique to gain initial access, tricking employees over the phone into handing over credentials or internal access.
When Cushman & Wakefield refused to pay, ShinyHunters followed through on their threat and dumped the stolen data publicly.
The leaked dataset was added to Have I Been Pwned (HIBP) on May 12, 2026, making it searchable for affected individuals.
The leaked records were largely business-oriented rather than financial, but the scope of exposure still poses a real risk.
The compromised data included:
While no passwords, financial records, or government IDs appear to have been included, the combination of professional contact data makes victims highly vulnerable to targeted spear-phishing, business email compromise (BEC), and social engineering attacks.
Threat actors routinely use this type of “corporate dossier” data to craft convincing fraudulent communications.
If you work with or for Cushman & Wakefield or have had professional dealings with the firm, take these steps immediately:
The ShinyHunters group is no stranger to high-profile breaches. The gang has previously been linked to attacks on Ticketmaster, AT&T, and Santander Bank, among others.
Their consistent use of vishing to bypass technical defenses highlights a growing trend: even organizations with strong perimeter security can fall victim when attackers target the human element directly.
Cushman & Wakefield has not disclosed the full details of how the intrusion occurred beyond confirming a vishing-based cyberattack.
Security teams across the real estate and financial services sectors should treat this incident as a reminder to reinforce employee awareness training, especially around phone-based social engineering.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post Cushman & Wakefield Data Breach Exposes 310,431 User Accounts appeared first on Cyber Security News.
UK politicians have strongly criticized GTA 6 developer Rockstar for its firing of 34 workers…
May is quite a big month for LEGO fans. Not only are there a wide…
Christopher Nolan has defended his upcoming movie, The Odyssey, from complaints about historical accuracy, after…
If you’re looking for recently released games to play on Switch, both Metroid Prime 4:…
Marvel fans are still puzzling over the decision to wrap up the wildly successful Ultimate…
Pokémon fans, it's time to clear out some space on your bookshelf, as the shiny…
This website uses cookies.