{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:17:16.420Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft","title":"Cushman & Wakefield confirms vishing-triggered Salesforce data theft","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Cushman & Wakefield","sector":"Professional Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters; Qilin also claimed the victim","summary":"Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.","how_it_worked":"The company's own statement names voice phishing as the cause. In this pattern a caller impersonating internal IT or a service provider contacts an employee about a supposedly urgent access issue and walks them through a login on a lookalike portal, capturing the password and the multi-factor response in real time. The stolen session gave the crew the employee's view of the firm's Salesforce tenant, from which client and corporate records were exported. Two extortion brands claiming the same victim within a day of each other points to shared or resold access.","lessons":"Phishing-resistant MFA plus export limits and alerting inside Salesforce would have blocked the login and capped what a single compromised seat could retrieve.","confidence":"Confirmed","sources":[{"title":"Two ransomware gangs now claim Cushman & Wakefield after Salesforce breach claim","url":"https://cybernews.com/news/cushman-wakefield-shinyhunters-salesforce-breach-claim/","publisher":"Cybernews"},{"title":"Cushman & Wakefield Hit by ShinyHunters Vishing Attack — 50GB Salesforce Data Dumped","url":"https://breached.company/cushman-wakefield-shinyhunters-vishing-salesforce-50gb-leak-2026/","publisher":"Breached.Company"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft"}]}