Cushman & Wakefield Data Breach Notice (Massachusetts Attorney General)
If you received a notice from Cushman & Wakefield, here’s what the filing says was exposed, and what to do about it.
Cushman & Wakefield notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on August 07, 2026, and the notice lists social security numbers among the information exposed.
The Social Security numbers of 20 Massachusetts residents are now in unknown hands following a data breach at Cushman & Wakefield. Because these numbers cannot be changed or replaced, the exposure creates a permanent risk of identity theft and tax fraud that will last for years.
A Number That Never Expires
The filing lists Social Security numbers as the information exposed in the incident. Unlike a credit card or password, a Social Security number is a lifelong identifier. It cannot be reissued on request the way other credentials can. Once it is out, it stays out. That single fact changes how you must think about protection: the goal is no longer prevention of exposure but lifelong monitoring and rapid response to any misuse.
The Massachusetts Attorney General’s office received the breach notice from Cushman & Wakefield on August 07, 2026. The record does not state when the incident itself occurred. The only reliable way to determine whether your information was included is to wait for direct notification from the company, which is required to contact affected individuals by mail. If you have not received such a letter, it is likely your records were not part of this filing. However, anyone who has moved since the incident should contact Cushman & Wakefield directly to confirm their status.
What Criminals Can Do With a Social Security Number Alone
A stolen Social Security number is valuable precisely because it is permanent. Fraudsters use it to file fraudulent tax returns before you do, open new accounts in your name, or claim government benefits. Because the number itself never changes, a breach today can produce consequences years from now when the data surfaces on dark-web marketplaces or is sold in bulk.
The filing does not indicate that any passwords, financial account numbers, or other credentials were exposed. This is genuinely good news. It means your existing Cushman & Wakefield account itself was not directly compromised, and you do not need to change any password related to the company. The risk is confined to identity theft made possible by the Social Security number.
Why the Small Number Matters
Only 20 people are named in this Massachusetts filing. Small scale does not mean small risk. When a limited number of records are taken, each one can receive more focused attention from criminals. A batch of 20 high-quality Social Security numbers can still generate significant fraudulent returns or loans. The limited scope also means the company was able to identify exactly whose records were involved, which increases the likelihood that every affected person will eventually receive a notification letter.
The Reality of Long-Term Identity Monitoring
Because the exposed data cannot be revoked, your defense must become continuous rather than one-time. Identity thieves often wait months or years before using stolen numbers, hoping victims have stopped watching. This makes sustained vigilance the only practical response.
Place a fraud alert or credit freeze with the three major credit bureaus immediately. A fraud alert requires lenders to verify your identity before opening new accounts. A credit freeze is stronger: it blocks new accounts entirely until you lift the freeze. Both are free and can be done online in minutes. Update these protections every time you move or change your contact information.
Review your tax transcripts from the IRS each year before filing season. This lets you spot fraudulent returns early. Sign up for IRS online account access so you receive alerts about any unusual activity tied to your Social Security number.
Monitor your credit reports from Equifax, Experian, and TransUnion at least quarterly. Look for accounts you did not open, addresses you do not recognize, or inquiries from lenders you never contacted. Each report is free once per week at AnnualCreditReport.com.
Consider placing an extended fraud alert that lasts seven years if you have already been a victim of identity theft in the past. This requires creditors to take extra steps to verify your identity and notifies you when someone tries to use your information.
Practical Steps That Address This Specific Exposure
- Contact Cushman & Wakefield directly if you have changed addresses since the incident to ensure they have your current information for notification.
- Place a credit freeze with Equifax, Experian, and TransUnion today. It is the single most effective way to block new-account fraud using your Social Security number.
- Set up IRS online account access and request a tax transcript each year to catch fraudulent filings before they affect your refund.
- Enroll in free credit monitoring offered by the company as part of their breach response. While not a complete solution, it provides an additional early-warning layer.
- Keep records of everything. Save the notification letter, dates you placed freezes or alerts, and any correspondence. These prove your diligence if identity theft occurs later.
The exposure of these 20 Social Security numbers is a permanent change in status for the people affected. The number cannot be cancelled or replaced. What you control now is how quickly you detect and respond when someone eventually tries to use it. Starting that monitoring immediately, and maintaining it for years, is the only practical defense this filing leaves available.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Cushman & Wakefield.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Cushman & Wakefield confirms vishing attack and Salesforce data breach
Commercial real estate firm Cushman & Wakefield confirmed a security incident triggered by a vishing…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…