Cushman & Wakefield Data Breach Notice (Vermont Attorney General)
If you are a customer of Cushman & Wakefield, here’s what’s now in circulation.
Cushman & Wakefield notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on August 07, 2026, and the notice lists social security numbers among the information exposed.
A Social Security number belonging to one of just two Vermont residents has been exposed in a data breach involving Cushman & Wakefield. The filing, submitted to the Vermont Attorney General on August 07, 2026, lists Social Security Numbers as the information involved. No other categories appear in the record.
What This Exposure Actually Means
If you received a notification from Cushman & Wakefield, your Social Security number is now in the hands of unknown parties. Unlike a password or credit card, a Social Security number cannot be changed. It remains permanently valuable to identity thieves because it never expires and serves as the primary key for opening accounts, filing taxes, claiming benefits, and committing long-term fraud in your name.
With only two people named in the Vermont filing, this is an unusually small incident. The small number does not reduce the risk to those affected. When a Social Security number leaves an organisation’s control, the potential harm lasts for years or decades.
The Permanent Nature of a Compromised SSN
A Social Security number is one of the few pieces of personal information that cannot be reissued on request the way a lost credit card or compromised password can. Once it is exposed, you must treat it as permanently public. Credit monitoring and fraud alerts become ongoing necessities rather than temporary precautions.
The record establishes no credential exposure. No passwords were exposed. This means the core account access to any Cushman & Wakefield services you hold remains secure. The threat is identity fraud built on the SSN itself, not direct takeover of an online account.
How to Determine Whether You Were Affected
Cushman & Wakefield is required to notify affected individuals directly, usually by mail. If you have not received a letter, your information was likely not included in this filing. However, letters can go to last-known addresses and may be delayed or lost. Anyone who has moved in recent years should contact the organisation directly to confirm whether their records were part of the incident. The filing does not state when the incident occurred, so the letter itself remains the clearest indicator available.
The Limited Scale and What It Changes
Only two Vermont residents appear in this specific filing. The same organisation also appears in the breach-notice registry of California, confirming the matter is not confined to one state. For the two individuals named here, the exposure is total and irreversible regarding the Social Security number.
Because the record lists only Social Security Numbers, the practical risks center on tax fraud, fraudulent loan applications, and medical identity theft tied to your number. These crimes do not require passwords. They require only enough additional personal details—often already available from other sources—to pass automated verification systems.
Why This SSN Exposure Carries Long-Term Risk
Thieves can use a stolen Social Security number to file fraudulent tax returns before you do, claim refunds that belong to you, or open lines of credit that damage your credit score. They can also use it in combination with publicly available information to impersonate you in government systems or healthcare settings. Because the number never changes, this risk does not diminish over time the way a breached password does after you reset it.
The absence of any other categories in the Vermont filing is meaningful. No financial account numbers, no dates of birth, and no additional identifiers beyond the SSN itself were listed. This narrows the immediate vectors but does not eliminate the core danger that comes with a permanently exposed government identifier.
Concrete Steps That Address This Specific Exposure
- Place a fraud alert or credit freeze with the three major credit bureaus immediately. This prevents new accounts from being opened in your name using the exposed Social Security number. A freeze is the stronger option and should be your default if you do not plan to apply for new credit soon.
- File your taxes as early as possible each year and monitor for IRS rejection notices. Identity thieves often file fraudulent returns early. Early filing reduces the window in which someone else can file using your number.
- Review every Explanation of Benefits statement from health insurers carefully. Medical identity theft tied to your SSN can result in bills or records appearing under your name at providers you have never visited.
- Request your annual free credit reports from Equifax, Experian, and TransUnion and check them for unfamiliar accounts. Continue this practice quarterly rather than once per year while the SSN remains exposed.
- Contact Cushman & Wakefield directly if you have moved since the incident or have not received a letter but believe you may have been a customer during the relevant period. Confirm whether your specific records were included.
This incident leaves you with fewer easy remedies than a typical breach because the key piece of information cannot be replaced. The focus must therefore shift from prevention of exposure—which has already occurred—to relentless monitoring and rapid response to any attempted misuse of your Social Security number.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Cushman & Wakefield.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Cushman & Wakefield confirms vishing attack and Salesforce data breach
Commercial real estate firm Cushman & Wakefield confirmed a security incident triggered by a vishing…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…