CUSHMAN & WAKEFIELD, INC.
bd_cdf44100b3bfaed9 · schema v1 · pii pii-v1
Full breach record for CUSHMAN & WAKEFIELD, INC. →2 incidents on fileCushman & Wakefield notified the Massachusetts Attorney General of a data security incident discovered on April 29, 2026. An unauthorized third party accessed and exfiltrated certain files containing personal data, including names. The company engaged third-party cybersecurity experts, reset credentials, implemented heightened monitoring, and notified law enforcement. No indication of misuse was found. Affected individuals are offered 24 months of Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 29, 2026
Discovered
Aug 7, 2026
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Siteshinyhuntersbd_94dad4d39b7268ca2026-05-03 · +96dVerified by operator
- Leak Siteqilinbd_f94238367dc882872026-05-03 · +96dVerified by operator
Regulatory filings (4) · sorted by filing gap
- Vermont State AGbd_1baa16367dbbe7a12026-08-07Verified by operator
- New Hampshire State AGbd_27631192cebaf0702026-08-07Verified
- California State AGbd_ad8121b21cc043a92026-08-07Verified by operator
- Pressshinyhuntersbd_73d80c5e639295172026-04-29 · +100dCandidate
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Apr 29, last Aug 7 (MA) — a 100-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.