What happened
Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.
How the deception worked
The company's own statement names voice phishing as the cause. In this pattern a caller impersonating internal IT or a service provider contacts an employee about a supposedly urgent access issue and walks them through a login on a lookalike portal, capturing the password and the multi-factor response in real time. The stolen session gave the crew the employee's view of the firm's Salesforce tenant, from which client and corporate records were exported. Two extortion brands claiming the same victim within a day of each other points to shared or resold access.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA plus export limits and alerting inside Salesforce would have blocked the login and capped what a single compromised seat could retrieve.
Sources (2)
- Two ransomware gangs now claim Cushman & Wakefield after Salesforce breach claimCybernews·cybernews.comOpen ↗
- Cushman & Wakefield Hit by ShinyHunters Vishing Attack — 50GB Salesforce Data DumpedBreached.Company·breached.companyOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.