Back to Blog
high severity May 05, 2026 · 6 min read

Cushman & Wakefield confirms vishing attack and Salesforce data breach

If you have an account with Cushman & Wakefield, here’s what’s now in circulation.

Commercial real estate firm Cushman & Wakefield confirmed a security incident triggered by a vishing (voice phishing) attack. ShinyHunters and Qilin claimed responsibility, alleging theft of over 500,000 Salesforce records containing PII and internal corporate data. The company engaged third-party experts and activated its incident response.

Cushman & Wakefield confirms vishing attack and Salesforce data breach

What happened

Cushman & Wakefield, a global commercial real estate services firm, confirmed that attackers gained access to its Salesforce environment after a successful vishing attack. The incident, publicly reported on May 5, 2026, involved the theft of more than 500,000 records containing personally identifiable information, Salesforce data, and internal corporate documents. Two threat groups, ShinyHunters and Qilin, claimed responsibility for the breach.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 637 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The attack began with voice phishing, in which perpetrators impersonated trusted individuals or authorities to trick employees into revealing credentials or approving unauthorized access. Once inside the network, the attackers targeted Salesforce, a cloud platform widely used for customer relationship management and holding sensitive client and employee data. Cushman & Wakefield stated it engaged third-party forensic experts and activated its incident response plan upon discovery.

The company has not released a full list of compromised data types, but the claims by ShinyHunters and Qilin suggest the stolen material includes names, contact details, addresses, and potentially financial or transactional records tied to commercial real estate deals. As of the latest updates, there is no confirmed evidence that the stolen data has been widely distributed on underground forums, though samples have reportedly been shown as proof of compromise.

Who's affected and why it matters

Current and former employees, business partners, and clients of Cushman & Wakefield are among those whose personal information may have been exposed. With more than 500,000 records involved, the breach reaches well beyond the company’s direct workforce into the broader ecosystem of real estate investors, property owners, tenants, and vendors whose details resided in the Salesforce instance. High-net-worth individuals and families who work with the firm on commercial property transactions or private real estate holdings are also potentially affected.

For executives and family offices, the exposure of PII linked to corporate real estate portfolios creates immediate risks of targeted fraud, spear-phishing, and impersonation. Attackers who possess both personal identifiers and internal deal information can craft highly convincing social engineering campaigns. The inclusion of Salesforce records raises the possibility that correspondence, contract details, or valuation data may also have been taken, increasing the chance of competitive intelligence theft or extortion attempts against corporate principals and their advisors.

The breach matters because real estate remains a favored sector for sophisticated threat actors seeking high-value targets. A single compromised record can serve as the starting point for long-term surveillance of an executive’s or family’s financial moves, travel patterns, and personal relationships. When such data is combined with information from other leaks, the potential for identity theft, account takeover, or physical security threats grows significantly.

The identity-chain implication

Modern data breaches rarely remain isolated events. A credential or personal record stolen from one organization frequently unlocks access to additional services where the same email address, phone number, or password has been reused. In the Cushman & Wakefield case, the harvested Salesforce data and PII can be fed into automated tools that cross-reference it against thousands of other breached datasets, revealing connections to banking platforms, investment accounts, health providers, and consumer services.

This identity-chain effect is particularly dangerous for executives and high-net-worth families whose professional and personal lives generate extensive digital footprints. A leaked business email from the breach could be tested against private wealth management portals or family office systems. Children’s gaming accounts are equally vulnerable in these chains; a parent’s reused password or linked phone number exposed in a corporate incident can lead to compromise of a child’s Roblox, Fortnite, or Steam account, which attackers then use as leverage for further extortion or to harvest additional family contacts.

Warden by GalaxyWarden offers continuous monitoring across 13.1B+ breach records and 100+ platforms, AI identity-chain mapping, hands-on remediation by specialists, and family/household coverage including children’s gaming accounts. Because credential leaks cascade into account takeovers and doxxing chains, protecting both corporate and personal identities, including gaming profiles, has become a necessary layer of defense for families with significant assets or public profiles.

What to do now

Executives and high-net-worth families connected to Cushman & Wakefield or similar real estate relationships should treat the breach as a prompt to strengthen their personal and household security posture immediately. Time is a critical factor; the longer exposed data circulates, the higher the probability that it will be combined with other leaks to create new attack paths.

  • Review all accounts that may share email addresses, phone numbers, or passwords used in professional correspondence with Cushman & Wakefield and change those credentials where possible, prioritizing financial services, investment platforms, and family office systems.
  • Enroll in dark web monitoring that tracks both corporate and consumer data sources, ensuring coverage extends to dependents and household members including children’s online gaming profiles.
  • Implement or reinforce multi-factor authentication on every account that supports it, favoring hardware keys or authenticator apps over SMS where feasible, and avoid reusing authentication methods across work and personal environments.
  • Contact Cushman & Wakefield’s designated breach response team to request confirmation of whether your specific records were involved and to obtain any remediation offers such as credit monitoring or identity theft insurance.
  • Schedule a professional security audit of home networks, personal devices, and family members’ gaming consoles or PCs to identify and close any entry points that could be exploited using data from this or linked breaches.

These steps, executed promptly and systematically, reduce the window of opportunity for attackers who may already possess fragments of the stolen information.

What this signals about the broader threat landscape

The Cushman & Wakefield breach highlights the growing effectiveness of vishing as an initial access technique against organizations that have hardened their technical defenses. Despite widespread adoption of email filtering, multi-factor authentication, and endpoint detection, voice-based social engineering continues to succeed because it exploits human trust rather than software vulnerabilities. Threat groups such as ShinyHunters and Qilin demonstrate increasing coordination, blending data theft with ransomware or extortion operations to maximize financial return.

For executives and families, the incident underscores that protection can no longer stop at the corporate perimeter. Personal and household digital identities are now integral parts of the attack surface. Real estate, finance, and professional services sectors remain prime targets because they concentrate high-value personal and transactional data. The speed with which stolen Salesforce records can be correlated with other breaches means that a single corporate incident can rapidly escalate into sustained targeting of individuals and their dependents.

The combination of vishing, cloud platform compromise, and identity chaining reflects a mature criminal economy in which data is treated as a raw material for automated, large-scale exploitation. Organizations and high-net-worth families alike must assume that their information will eventually appear in multiple datasets and build resilience through continuous monitoring, strict credential hygiene, and active remediation rather than relying solely on prevention. The breach serves as a reminder that privacy and security have become inseparable from reputation and asset protection at the executive and family level.

Source: Cybernews

What You Should Do

  1. Watch for spear-phishing or follow-up vishing calls
  2. Verify any unexpected vendor or client communications
  3. Monitor accounts for unusual access
  4. Report suspicious activity to your organization

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample637 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Cushman & Wakefield customer?
Cushman & Wakefield is one breach. Your email is probably in others.
over 500,000 records accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed May 05, 2026
Last reviewed July 22, 2026
Affected over 500,000 records
Data exposed personally identifiable informationSalesforce recordsinternal corporate data
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Sources: Cybernews
Share this Post on X Reddit Email