Cushman & Wakefield Data Breach Exposes Names and Personal Information

Real Estate data breach illustration
Breach Discovery: April 2026Breach Notification: August 2026

What Happened in the Cushman & Wakefield Data Breach?

Cushman & Wakefield has confirmed a data security incident after discovering that an outside party gained unauthorized access to its network. The company detected the intrusion and began looking into it right away. As a result, affected individuals are now receiving formal notice describing what took place.

According to the notification, unauthorized access to the company’s systems occurred in April 2026. During this time, an unauthorized third party was able to access certain files and remove them from the network. This means the intrusion was not simply a case of someone peeking at data; files were actually copied out of the environment.

Once the company became aware of the incident, it launched a thorough review to figure out exactly what happened. This process included examining a large amount of data and files to determine whose personal information was involved. Because of the scale of that review, the investigation took time before individual notifications went out in August 2026. The company has stated it found no indication that anyone actually viewed or misused the exposed data, though it chose to notify affected people out of caution.

Who was affected?

The notification letter was sent to individuals whose personal data was found in the files accessed during the breach. Cushman & Wakefield has not publicly disclosed the total number of people affected by this incident. Given the company’s global real estate services business, the affected population could include employees, clients, tenants, or other individuals connected to its operations.

Because the notice was filed with the California Attorney General, at least some affected individuals are California residents. However, the source does not specify whether minors were involved or whether the exposure was limited to a particular business unit. Anyone who receives a notification letter directly from the company should treat it as confirmation that their information was part of the exposed files.

What Information Was Potentially Exposed?

The notification indicates that names were involved in the breach, along with additional personal data specific to each recipient. Because notification letters are often personalized, the exact combination of exposed information can vary from person to person. Below are the categories referenced in the company’s disclosure.

  • Full name
  • Additional personal data specific to the individual, as detailed in each personalized notice

Even when a breach does not include obvious financial account numbers, exposed names paired with other personal details can still create real risk. For example, scammers often use partial personal information to craft convincing phishing emails or phone calls that appear legitimate. This tactic, sometimes called pretexting, relies on victims believing the sender already knows something true about them.

In addition, any exposed identification-related information could be combined with data from other breaches to build a fuller profile of a person. As a result, individuals should not assume limited exposure means limited risk. Criminals frequently piece together small amounts of data from multiple sources to attempt identity theft or account takeover fraud.

What is the company doing?

Once Cushman & Wakefield learned of the incident, it moved to secure its network with help from outside cybersecurity specialists. The company reset passwords and access credentials across its systems as a precaution. It also put stronger monitoring in place to watch for further suspicious activity.

Beyond these immediate steps, the company says it continues to monitor for signs that the stolen data is being misused. It has notified law enforcement so the incident can be properly investigated. The company has also committed to taking further remedial action if new issues arise, and it directed affected individuals to additional resources describing recommended precautions.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone notified about this breach should request a copy of their credit report and review it closely for unfamiliar accounts or inquiries. Under federal law, consumers can obtain a free credit report from each of the three major bureaus every year. Checking these reports regularly makes it easier to catch fraud early.

Because identity thieves sometimes wait months before using stolen data, ongoing monitoring matters more than a single check. Setting a recurring reminder to review your reports every few months can help you spot problems before they grow. If you notice anything suspicious, report it to the credit bureau immediately.

Consider a Fraud Alert or Credit Freeze

Individuals concerned about misuse of their personal information may want to place a fraud alert on their credit file. A fraud alert tells lenders to take extra steps to verify your identity before opening new credit in your name. This is a free, simple step that stays active for one year and can be renewed.

For stronger protection, you can also request a credit freeze, which blocks most new creditors from viewing your credit file altogether. This makes it much harder for someone to open a new account using your name. You can freeze and later lift the freeze whenever you need to apply for credit yourself.

Watch for Phishing Attempts

Because your name and other personal details were involved in this breach, you should be cautious of unexpected emails, texts, or phone calls referencing this incident. Scammers often use real breach events to make phishing attempts seem more believable. Never click links or share information in response to unsolicited messages.

Instead, if you receive a message claiming to be from Cushman & Wakefield or a related service, contact the company directly using a verified phone number or website. This helps confirm whether the communication is genuine. Taking a moment to verify can prevent a costly mistake.

Know Your Legal Options

If you received a breach notification letter, you may have legal options worth exploring, depending on how your information was used or exposed. Consulting with a data breach attorney can help clarify whether you qualify for compensation or participation in a potential class action. Many attorneys offer a free initial case evaluation.

Because deadlines for filing legal claims can be limited, it’s wise to act promptly rather than wait. An attorney can also help you understand what documentation to keep, including the notification letter itself and any evidence of related suspicious activity affecting your accounts.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

Check other recent data breach notifications →