Cushman & Wakefield vishing data incident

Cushman & Wakefield confirmed a limited data-security incident caused by vishing. A verified HIBP corpus primarily consisting of company and external business-contact data associated with the incident.

Last modified

Summary

  • Environment: HIBP description; no actor identity, ransom demand, publication completeness, or alleged source platform is asserted.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Cushman & Wakefield confirmed a limited data-security incident caused by vishing. [2]

Impact

A verified HIBP corpus primarily consisting of company and external business-contact data associated with the incident. [1]

Documented data types include:

  • Contact information — Email addresses, phone numbers, and company physical addresses listed in HIBP for the verified primarily-business-information corpus. [1]
  • Names — Names listed in HIBP for the verified corpus. [1]
  • Employment information — Job titles listed in HIBP for the primarily business-information corpus. [1]

A cited record reports 310,431 records (Unique email addresses represented in the verified HIBP corpus; not a company-confirmed number of clients, employees, records, or affected individuals; as of 2026-05-12). [1]

HIBP reported that associated data was published publicly after the incident. [1]

Timeline

  1. Public disclosure

    Date The Register published the company’s direct statement.

    [2]
  2. Documented event

    HIBP BreachDate and date of the first reviewed company statement; neither source establishes this as the exact initial-access date.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Cushman & Wakefield described the incident as limited in scope and caused by vishing. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

Response

The company activated response protocols, took steps to contain unauthorized activity, and engaged third-party expert advisors. Cushman & Wakefield said its systems and operations continued to run normally while it investigated. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]