Ransomware victim disclosure
← All victimsCushman & Wakefield Inc.
Claimed by shinyhunters · listed 18 days ago
Status timeline
- Listed
May 3, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- US
- Sector
- Business Services
- Listed on leak site
- May 3, 2026
About the victim
AI dossier — public-source company profileCushman & Wakefield Inc. is a leading global commercial real estate services firm headquartered in Chicago, Illinois. The company provides a broad range of services including property leasing, capital markets, facilities management, and valuation advisory across more than 60 countries. It is one of the largest commercial real estate services companies in the world by revenue and headcount.
- Industry
- Commercial Real Estate Services
- Address
- 225 West Wacker Drive, Chicago, Illinois 60606, USA
- Employees
- 50000+
- Founded
- 1917
Attack summary
Severity: critical — The group claims exfiltration of over 500,000 records containing PII at scale from a Salesforce environment, constituting a large-volume regulated personal data breach affecting clients, employees, or counterparties of a major global real estate firm.ShinyHunters claims to have exfiltrated over 500,000 Salesforce records containing personally identifiable information and internal corporate data, and is threatening further 'digital problems' unless the company makes contact by 6 May 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally Identifiable Information (PII)
- Internal corporate data
What the group claims
Over 500k Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 6 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 3 May 2026 | Warning: FINAL WARNING
Sources
- Victim sitecushmanwakefield.com
Source
Indexed 18 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
