
Cushman & Wakefield, a leading global commercial real estate services firm based in Chicago, disclosed a data breach that occurred in April 2026.
The breach was reported to the attorneys general offices of California and Massachusetts on Aug. 7, 2026. The company's notification letters to affected consumers are dated Aug. 7, 2026. The total number of people affected in the United States has not been publicly disclosed.
Cushman & Wakefield discovered suspicious activity on its network on April 29, 2026. An unauthorized third party gained access to Cushman & Wakefield's systems and exfiltrated, or removed, certain files.
On May 3, 2026, ShinyHunters, a ransomware group, posted on the Tor network, alleging that they had breached Cushman & Wakefield. The group claimed the compromised dataset included personally identifiable information and other internal corporate data.
Following discovery, Cushman & Wakefield undertook a comprehensive review of the affected data. This review involved analyzing a substantial volume of data and files to determine which individuals were affected and the nature of the information involved.
The type of consumer information confirmed as exposed included names and Social Security numbers.
The company is offering 24 months of complimentary access to Experian IdentityWorks.
Affected individuals can enroll by visiting Experian's enrollment page and entering the activation code included in their notification letter. The deadline to enroll is Nov. 30, 2026, by 11:59 p.m. UTC.
For questions about the service or help with identity restoration related to this incident, affected individuals can call 833-918-6825, Monday through Friday from 8 a.m. to 8 p.m. Central Time, excluding major U.S. holidays.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)