TL;DR: Cushman & Wakefield, the global commercial real estate firm managing $79 billion in assets, got claimed by two separate ransomware groups in the same week. ShinyHunters says it vished its way into the company's Salesforce tenant on May 1 and stole 500,000+ records containing client contacts, deal histories, financial records, and confidential communications. Qilin (currently the world's most prolific ransomware operation) listed Cushman & Wakefield on its own leak site on May 4. The company calls the incident "limited" and says systems are running normally. ShinyHunters' deadline to pay or see the data published is today, May 6.
One Company, Two Gangs, One Week
Here is how fast things moved:
- May 1: ShinyHunters claims to have breached Cushman & Wakefield through a vishing attack targeting an employee
- May 3: Breach details surface on threat intelligence trackers
- May 4: Qilin, a separate ransomware group, independently lists Cushman & Wakefield on its own Tor leak site
- May 5: Cushman & Wakefield confirms "a limited data security incident due to vishing" to The Register [1]
- May 6: ShinyHunters' pay-or-leak deadline hits
Two ransomware operations hitting the same target in the same week is unusual. The Register reports the attacks appear to be separate, coincidentally timed operations rather than a coordinated effort [1]. That is somehow worse: it means Cushman & Wakefield's defenses were permeable enough that two unrelated groups found their way in around the same time.
What ShinyHunters Says It Stole
ShinyHunters claims to have exfiltrated more than 500,000 Salesforce records from Cushman & Wakefield's CRM environment. The stolen data allegedly includes [2][3]:
- Client contacts: names, emails, phone numbers of property owners, tenants, and investors
- Deal histories: transaction records for commercial real estate deals
- Financial records: lease terms, valuations, revenue figures
- Confidential communications: internal messages and client correspondence
Cushman & Wakefield manages or leases 5.4 billion square feet of commercial space globally. Its client list reads like a Fortune 500 index. If those deal histories and financial records are real, the leak would expose not just Cushman & Wakefield's data, but the commercial real estate strategies, property valuations, and financial positions of its clients.
This is not like stealing a consumer database full of email addresses. Commercial real estate intelligence is competitive ammunition. A leaked portfolio of lease terms and deal structures gives competitors (or hostile acquirers) a roadmap of exactly what properties are worth and what tenants are paying.
The Vishing Playbook, Again
Cushman & Wakefield confirmed the attack started with vishing: voice phishing. Someone called an employee, pretended to be someone they were not, and talked their way into access [1].
If this sounds familiar, it should. ShinyHunters has been running this exact playbook for over a year. The group calls help desk or sales operations staff, social-engineers them into authorizing a malicious connected app in the target's Salesforce tenant, then uses the app's API access to bulk-export data at speed [2].
We have covered this campaign extensively. The victim list using this same Salesforce vishing technique now includes:
- ADT: 10 million records via Okta SSO vishing
- Kemper Corporation: 13 million Salesforce records
- Canada Life: 5.6 million Salesforce records
- Instructure (Canvas): 275 million users, 3.65 TB
- Crunchyroll, Wynn Resorts, Panera Bread, and dozens more
The pattern is always the same: a phone call, a fast-talking pretender, a Salesforce connected app, and a bulk data export before anyone notices. Cushman & Wakefield is at least the 30th major organization hit by this campaign since late 2025.
The Qilin Question
Three days after ShinyHunters listed Cushman & Wakefield, Qilin showed up with its own listing.
Qilin is not a minor player. It is currently considered the most prolific ransomware group in the world, having overtaken LockBit in volume of attacks. Its previous targets include NHS hospital contractors in the UK, Australian logistics firms, and European manufacturers [1].
Qilin has not specified what data it claims to have stolen from Cushman & Wakefield. The group's leak site listing appeared May 4 without the level of detail ShinyHunters provided.
Two possible explanations: either Qilin found a separate entry point around the same time ShinyHunters did (suggesting systemic security weaknesses) or one group's initial breach created noise or instability that attracted the other. Neither explanation is reassuring if you are a Cushman & Wakefield client.
The Company's Response
Cushman & Wakefield told The Register it "recently became aware of a limited data security incident due to vishing" and "activated its response protocols, including taking steps to contain the unauthorized activity and engaging third-party expert advisors" [1].
The company said its systems and operations "continue to run normally."
Notice what is missing from that statement: any acknowledgment of ShinyHunters' specific claims about 500,000 Salesforce records, any mention of Qilin's separate listing, and any indication that clients have been notified.
Calling a breach that attracted two ransomware groups and exposed half a million CRM records "limited" is the kind of statement that tends not to age well.
What Happens Today
ShinyHunters set May 6 as the deadline for Cushman & Wakefield to make contact, presumably to negotiate a payment. The group's message on its leak site: "This is a final warning to reach out by 6 May 2026 before we leak along with several annoying (digital) problems that'll come your way" [2][3].
That threat of "annoying digital problems" is vague but deliberate. It could mean anything from a staged data dump to denial-of-service attacks to further system compromises.
ShinyHunters has a strong track record of following through. When Instructure failed to respond by the group's Canvas deadline, ShinyHunters extended the deadline, then began publishing school lists. When ADT went quiet, the data surfaced on dark web markets within weeks.
If Cushman & Wakefield does not pay:
- Client deal data hits dark web forums, where real estate competitors, short sellers, and corporate intelligence firms will find it within hours
- Contact databases become fuel for targeted spear-phishing campaigns against Cushman & Wakefield's high-net-worth clients
- Financial records expose lease terms and property valuations that companies pay consultants six-figure fees to keep confidential
The Salesforce Problem Nobody Wants to Talk About
Cushman & Wakefield is now one of more than 30 major organizations breached through ShinyHunters' Salesforce campaign. The attack vector is not some exotic zero-day. It is a phone call followed by a connected app authorization.
Salesforce connected apps are legitimate features that allow third-party integrations to access CRM data through APIs. The problem is that authorizing a new connected app often requires nothing more than a single employee clicking "Allow", and vishing is extremely effective at getting people to click "Allow."
Once authorized, the connected app has API-level access to export entire Salesforce objects: contacts, opportunities, accounts, cases, and custom objects. ShinyHunters automates the extraction and has it down to a science. In several confirmed cases, the group had bulk-exported the entire tenant before the target organization realized anything was wrong.
This is a systemic Salesforce ecosystem problem, not just a Cushman & Wakefield problem. Salesforce has over 150,000 enterprise customers. The connected app authorization workflow has not fundamentally changed despite a year of attacks exploiting it.
What to Do If You Are a Cushman & Wakefield Client
- Assume your data is compromised. If your organization has done business with Cushman & Wakefield (property management, leasing, investment sales, appraisal) your deal terms and contact information may be in the stolen dataset.
- Watch for targeted phishing. Attackers who have your name, company, and the specifics of your real estate transactions can craft extremely convincing emails. Any message referencing a specific property, lease, or deal term that arrives unsolicited should be treated as suspicious.
- Review what Cushman & Wakefield has in your file. Ask your Cushman & Wakefield contact what data categories they hold on your organization. Under state privacy laws in California, Virginia, Colorado, and Connecticut, you have the right to request this.
- Monitor your domain for impersonation. Stolen client contact lists are often used to register lookalike domains for business email compromise attacks. Set up alerts for domain registrations similar to your company name.
- Ask about notification. If Cushman & Wakefield has not contacted you about this incident, ask why. Data breach notification laws in most states require notification within 30 to 60 days of discovery.
Sources
- The Register: Cushman & Wakefield confirms vishing cyberattack (May 5, 2026)
- Cybernews: ShinyHunters adds Cushman & Wakefield to Salesforce hacking spree, claims data theft (May 2026)
- RedPacket Security: ShinyHunters Ransomware Victim: Cushman & Wakefield Inc (May 2026)
- BreachSense: Cushman and Wakefield Data Breach 2026