---
title: "Cushman & Wakefield vishing data incident"
description: "Evidence-backed account of Cushman & Wakefield vishing data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/cushman-wakefield-vishing-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/cushman-wakefield-vishing-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/cushman-wakefield-vishing-data-incident-2026/stix.json"
---

# Cushman & Wakefield vishing data incident

Cushman & Wakefield confirmed a limited data-security incident caused by vishing. A verified HIBP corpus primarily consisting of company and external business-contact data associated with the incident.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** HIBP description; no actor identity, ransom demand, publication completeness, or alleged source platform is asserted.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[Cushman & Wakef](https://www.cushmanwakefield.com/)ield confirmed a limited data-security incident caused by vishing. [2](#source-2)

## Impact

A verified HIBP corpus primarily consisting of company and external business-contact data associated with the incident. [1](#source-1)

Documented data types include:

- Contact information — Email addresses, phone numbers, and company physical addresses listed in HIBP for the verified primarily-business-information corpus. [1](#source-1)
- Names — Names listed in HIBP for the verified corpus. [1](#source-1)
- Employment information — Job titles listed in HIBP for the primarily business-information corpus. [1](#source-1)

A cited record reports 310,431 records (Unique email addresses represented in the verified HIBP corpus; not a company-confirmed number of clients, employees, records, or affected individuals; as of 2026-05-12). [1](#source-1)

HIBP reported that associated data was published publicly after the incident. [1](#source-1)

## Timeline

### May 5, 2026 — Public disclosure

Date The Register published the company's direct statement. [2](#source-2)

### May 5, 2026 — Documented event

HIBP BreachDate and date of the first reviewed company statement; neither source establishes this as the exact initial-access date. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Cushman & Wakefield described the incident as limited in scope and caused by vishing. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- [T1566.004 — Phishing: Spearphishing Voice](https://attack.mitre.org/techniques/T1566/004/) [2](#source-2)

## Response

The company activated response protocols, took steps to contain unauthorized activity, and engaged third-party expert advisors. Cushman & Wakefield said its systems and operations continued to run normally while it investigated. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/cushman-wakefield-vishing-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Cushman & Wakefield breach record

advisory · Have I Been Pwned · May 12, 2026

<https://haveibeenpwned.com/api/v3/breach/CushmanWakefield>

<a id="source-2"></a>

### Cushman & Wakefield confirms vishing cyberattack

news · The Register · May 5, 2026

<https://www.theregister.com/security/2026/05/05/cushman-wakefield-confirms-vishing-cyberattack/5228718>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   May 2026 Cushman & Wakefield vishing incident: The company activated response protocols, took steps to contain unauthorized activity, and engaged third-party expert advisors.
2. **Used Attack Technique · 95% confidence · current**  
   May 2026 Cushman & Wakefield vishing incident: https://attack.mitre.org/techniques/T1566/004/
3. **Exposed Data Category · 100% confidence · current**  
   Cushman & Wakefield business-contact data corpus: Contact information
4. **Disclosed At · 100% confidence · current**  
   May 2026 Cushman & Wakefield vishing incident: 2026-05-05
5. **Resulted In · 95% confidence · current**  
   May 2026 Cushman & Wakefield vishing incident: Cushman & Wakefield business-contact data corpus
6. **Exposed Record Count · 100% confidence · current**  
   Cushman & Wakefield business-contact data corpus: 310,431 record
7. **Resulted In · 100% confidence · current**  
   May 2026 Cushman & Wakefield vishing incident: Cushman & Wakefield said its systems and operations continued to run normally while it investigated.
8. **Affected Organization · 100% confidence · current**  
   May 2026 Cushman & Wakefield vishing incident: Cushman & Wakefield plc
9. **Occurred At · 85% confidence · current**  
   May 2026 Cushman & Wakefield vishing incident: 2026-05-05
10. **Exposed Data Category · 100% confidence · current**  
   Cushman & Wakefield business-contact data corpus: Names
11. **Exposed Data Category · 100% confidence · current**  
   Cushman & Wakefield business-contact data corpus: Employment information
12. **Resulted In · 90% confidence · current**  
   Cushman & Wakefield business-contact data corpus: HIBP reported that associated data was published publicly after the incident.
13. **Resulted In · 100% confidence · current**  
   May 2026 Cushman & Wakefield vishing incident: Cushman & Wakefield described the incident as limited in scope and caused by vishing.

</details>
