CUSHMAN & WAKEFIELD, INC.
bd_ad8121b21cc043a9 · schema v1 · pii pii-v1
Full breach record for CUSHMAN & WAKEFIELD, INC. →2 incidents on fileCushman & Wakefield notified the California AG of a data breach where an unauthorized third party accessed and exfiltrated files between April 21 and April 29, 2026. The company became aware of the incident on April 29, 2026. Affected data includes names and potentially other personal information. The company engaged third-party cybersecurity experts, reset credentials, implemented heightened monitoring, and notified law enforcement. Complimentary identity monitoring is being offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 21, 2026
Begins
Apr 29, 2026
Discovered
Aug 7, 2026
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Siteshinyhuntersbd_94dad4d39b7268ca2026-05-03 · +96dVerified by operator
- Leak Siteqilinbd_f94238367dc882872026-05-03 · +96dVerified by operator
Regulatory filings (4) · sorted by filing gap
- Vermont State AGbd_1baa16367dbbe7a12026-08-07Verified by operator
- New Hampshire State AGbd_27631192cebaf0702026-08-07Verified
- Massachusetts State AGbd_cdf44100b3bfaed92026-08-07Verified by operator
- Pressshinyhuntersbd_73d80c5e639295172026-04-29 · +100dCandidate
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Apr 29, last Aug 7 (CA) — a 100-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.