TL;DR: ShinyHunters set a May 6 deadline for Cushman & Wakefield to negotiate. The commercial real estate giant didn't respond. So ShinyHunters published roughly 50GB of Salesforce data: over 500,000 records containing personally identifiable information and internal corporate data. The group's message: "They simply don't care." This matters beyond one company's breach because the same group, ShinyHunters, has set a May 12 deadline for the Canvas/Instructure breach affecting 275 million students. What just happened to Cushman & Wakefield is a preview of what Monday could look like for thousands of schools.
What Just Happened
On May 1, ShinyHunters claimed they'd breached Cushman & Wakefield through a vishing attack: old-fashioned social engineering over the phone. An employee was tricked into granting access. From there, ShinyHunters extracted over 500,000 records from the company's Salesforce environment [1][2].
Three days later, on May 4, a second ransomware group (Qilin, currently one of the most active ransomware operations globally) listed Cushman & Wakefield on its own leak site. Two gangs, same target, same week. No evidence the groups coordinated. Just a company with enough vulnerabilities that two separate crews found their way in [2][3].
ShinyHunters gave Cushman & Wakefield until May 6 to make contact. The company didn't respond. So on May 9, ShinyHunters uploaded the full dataset, approximately 50GB, to their leak site. Cybernews researchers began downloading the files and confirmed the scale [1].
ShinyHunters' statement was blunt: Cushman & Wakefield "simply don't care" despite "all the chances and offers made" [1].
What's in the Data
The published dataset contains over 500,000 Salesforce records. ShinyHunters claims these include PII (names, contact information, and other personally identifiable data) along with internal corporate records [1][2].
Cushman & Wakefield is one of the world's largest commercial real estate firms. They manage office buildings, retail spaces, and industrial properties across 60 countries. Their Salesforce environment holds client data, tenant information, property management records, and business communications. That's the kind of data that makes identity theft trivial and corporate espionage lucrative.
The company called the breach "limited" in scope [3]. Fifty gigabytes of published Salesforce records is an unusual definition of "limited."
The ShinyHunters Playbook
This wasn't random. ShinyHunters runs a consistent escalation pattern, and Cushman & Wakefield followed it step by step:
- Breach and claim. Announce the attack publicly. Name the victim. State what was stolen.
- Set a deadline. Give the company a window to negotiate, typically 3-7 days.
- Wait for contact. If the company engages, negotiate a ransom. If not, move to step 4.
- Publish everything. Dump the full dataset on the leak site. Make an example of them.
Cushman & Wakefield hit every stage. Breach on May 1. Deadline on May 6. Silence from the company. Data published by May 9.
Since March 2026, ShinyHunters has targeted ADT, Carnival Cruise Line, Rockstar Games, Vimeo, Medtronic, Canvas/Instructure, and now Cushman & Wakefield [2]. Their February 2026 spree alone hit more than 15 companies. The group isn't picking random targets. They're going after companies with massive Salesforce deployments, customer databases, and enough data to make the threat credible.
Why This Matters: The Canvas Deadline Is Monday
Here's the part that should keep university administrators up at night.
ShinyHunters has set a May 12 deadline for Canvas/Instructure, the learning management system used by 9,000 educational institutions and 275 million students. That deadline is Monday. Two days from now.
The Cushman & Wakefield data dump isn't just another breach story. It's a signal. ShinyHunters follows through. They set deadlines. When those deadlines pass without payment, they publish. Every time.
The Canvas breach is orders of magnitude larger: 3.65 terabytes of data, 275 million affected users, student records from elementary schools through graduate programs. If ShinyHunters follows the same playbook they used on Cushman & Wakefield (and nothing in their pattern suggests they won't) Monday could mean the largest education data dump in history.
A Phone Call Took Down a $10 Billion Company
The attack vector deserves attention. ShinyHunters didn't exploit a zero-day. They didn't breach a firewall. They called someone on the phone [3].
Vishing (voice phishing) is social engineering delivered by phone. An attacker impersonates IT support, a vendor, or a colleague. They talk an employee into granting access, sharing credentials, or approving a request they shouldn't. It works because humans trust voices more than emails.
Cushman & Wakefield has a $10 billion market cap and global operations across 60 countries. Their cybersecurity budget is almost certainly in the tens of millions. And a single phone call to a single employee gave attackers access to their entire Salesforce environment.
This is the same attack vector ShinyHunters used in their broader Salesforce campaign. The group's SSO campaign targeting 100+ companies relied heavily on social engineering. Technical defenses don't help when the attack targets human judgment.
Cushman & Wakefield's Response: "Limited"
Cushman & Wakefield's official statement followed the standard corporate breach playbook: "We have activated our response protocols, including taking steps to contain the unauthorized activity and engaging third-party expert advisors to support a comprehensive response. Our systems and operations continue to run normally" [3].
They called the incident "limited in scope." Then 50GB of their Salesforce data showed up online.
The decision not to pay ShinyHunters isn't necessarily wrong. Law enforcement and security experts generally advise against paying ransoms: it funds criminal operations and doesn't guarantee data deletion. But "limited" is a messaging choice that insults the intelligence of anyone whose PII is now available for download.
What to Do if You're Affected
If you've done business with Cushman & Wakefield (as a tenant, client, vendor, or employee) assume your data is in this dump until proven otherwise.
- Freeze your credit. All three bureaus. It's free and takes five minutes. This is non-negotiable after a PII dump of this size
- Change passwords for any account that shared credentials with a Cushman & Wakefield portal or Salesforce login
- Watch for targeted phishing. Attackers who buy this data will use real details from these records to craft convincing emails. If someone references your lease terms, property address, or business relationship with C&W, verify through a known phone number before clicking anything
- Monitor your accounts. Set up fraud alerts if credit freezes aren't practical for your situation. Review bank and credit card statements weekly
- Document everything. If you're considering joining a class action (and given Medtronic's 6+ lawsuits, one is likely coming) keep records of the breach notification, any suspicious activity, and your mitigation steps
The Clock Is Ticking
Cushman & Wakefield is done. The data is out. The damage is measured in months and years of identity monitoring and fraud exposure for half a million people.
But the bigger story is what this means for Monday. ShinyHunters just demonstrated, again, that their deadlines aren't bluffs. They set a date. They published the data. They're already moving on to the next target.
That next target is Canvas. 275 million students. 9,000 schools. 3.65 terabytes of educational records.
Monday is two days away.
References
Published: May 10, 2026