CUSHMAN & WAKEFIELD, INC.
bd_73d80c5e63929517 · schema v1 · pii pii-v1
Full breach record for CUSHMAN & WAKEFIELD, INC. →2 incidents on filePress / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Cushman & Wakefield: Cushman&Wakefield was the victim of a data breach on April 29, 2026, during which an unauthorized third party accessed certain files containing personal data and exfiltrated them. This breach may have resulted in unauthorized access to the victim's name and other personal data. There is no indication that this personal information was viewed or misused. A cyberattack was claimed by Qilin on May 4, 2026. Linked ransomware group: shinyhunters.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Apr 29, 2026
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Siteshinyhuntersbd_94dad4d39b7268ca2026-05-03 · +4dVerified by operator
- Leak Siteqilinbd_f94238367dc882872026-05-03 · +4dVerified by operator
Regulatory filings (4) · sorted by filing gap
- Vermont State AGbd_1baa16367dbbe7a12026-08-07 · +100dVerified by operator
- New Hampshire State AGbd_27631192cebaf0702026-08-07 · +100dVerified
- California State AGbd_ad8121b21cc043a92026-08-07 · +100dVerified by operator
- Massachusetts State AGbd_cdf44100b3bfaed92026-08-07 · +100dVerified by operator
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Apr 29, last Aug 7 (MA) — a 100-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
shinyhunters
According to ransomware.live, ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.