Cushman & Wakefield Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Cushman & Wakefield disclosed a data breach on May 05, 2026, affecting 310,000 individuals. Email addresses, job titles, names, phone numbers, and physical addresses were exposed; anyone who may have been impacted should review the company’s notices and consider protective steps.
Inside the incident
The group published the data after issuing a “pay or leak” demand. The material consisted of business contact records that included names, job titles, salutations, email addresses, phone numbers and physical addresses. Both internal Cushman & Wakefield email addresses and a large number of external addresses appeared in the release. The precise circumstances of the intrusion and whether additional data were obtained remain undisclosed.
Who is qilin?
Qilin is a ransomware-as-a-service operation that first appeared in public reporting in 2022. The group typically uses double-extortion tactics, encrypting systems and threatening to publish stolen data unless a ransom is paid. It has claimed responsibility for intrusions across multiple industries and maintains a leak site where it lists victims and, in some cases, posts sample files. Claims made on the site are not independently verified by the victims in every instance.
About Cushman & Wakefield
Cushman & Wakefield is a global provider of commercial real estate services, including property management, leasing, investment sales and facilities management. Organisations of this type routinely maintain large directories of employees, clients, vendors and building occupants. These directories contain the names, titles, direct contact details and office addresses needed to conduct day-to-day business.
What was likely exposed
The published data included email addresses, job titles, names, phone numbers, physical addresses and salutations. Public statements have not confirmed whether additional categories of information, such as financial records or internal documents, were also taken. The exact contents of any unreleased material therefore remain unconfirmed.
Why it matters
Contact data of this nature can be used to craft targeted phishing messages or to map organisational structures for social-engineering attacks. Individuals whose details appeared may receive an increased volume of unsolicited messages. For the company, the incident adds to the body of publicly available information about its personnel and business relationships, which can be referenced in future campaigns against the firm or its clients.
Were you affected?
Individuals can review any recent unsolicited messages that reference Cushman & Wakefield and consider whether the sender had access to the types of details listed above. Running a free exposure scan of an email address against known breach datasets provides one way to check whether the address has appeared in previously published collections. Organisations that hold similar contact directories can review access controls and logging around those systems.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
BCD Travel Data Breach (2026)DentaQuest Data Breach (2026)Baker Distributing Data Breach (2026)Vimeo Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the Cushman & Wakefield Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.