Cushman & Wakefield, one of the largest commercial real estate services firms in the world, has disclosed that an unauthorized third party gained access to its systems and exfiltrated certain company data. Companies that collect and store sensitive personal information have a responsibility to protect it from unauthorized access, and a breach of this nature can leave affected individuals vulnerable to fraud and identity theft.
Cushman & Wakefield’s Data Breach Investigation
Cushman & Wakefield reported that on April 29, 2026, it became aware of unauthorized access to its network by a third party, who the company determined was able to exfiltrate certain files. Following discovery of the incident, Cushman & Wakefield undertook what it described as a diligent, comprehensive review of the affected data and files to determine which individuals were impacted and what categories of personal information were involved. That review reportedly confirmed that certain personal data relating to affected individuals was accessed and taken by the unauthorized third party.
In the notification letters Cushman & Wakefield began sending to affected individuals, the company stated it has seen no indication that the accessed information has actually been viewed or misused by the unauthorized party. Out of an abundance of caution, the company chose to notify potentially affected individuals and offer them access to identity protection resources. Cushman & Wakefield says it has since reset system passwords and access credentials, implemented heightened monitoring across its network, and notified law enforcement about the incident.
Breaches involving large commercial and professional services firms are an increasingly common target for cybercriminals, in part because these companies often maintain large repositories of personal and financial data belonging to employees, clients, tenants, and business partners. A single successful intrusion can expose records covering thousands of individuals across many different relationships with the company, which is part of why this type of incident routinely triggers state-mandated notification requirements once an investigation confirms unauthorized access.
Cyberattacks such as this one frequently follow a similar pattern: an outside actor gains unauthorized entry into a company’s network, quietly copies or exfiltrates files before detection, and only then triggers the company’s incident-response and legal-notification obligations. The gap between initial intrusion and public notification can leave affected individuals unaware for weeks or months that their information may be circulating outside the company’s control, which is one reason regulators require prompt notice once an investigation is far enough along to identify who was affected.
When names are exposed in combination with other personal identifiers, affected individuals can face an elevated risk of follow-up phishing attempts, where scammers use breach notifications as a pretext to send fraudulent emails or texts requesting additional personal or financial details. Consumers who receive a notification letter from Cushman & Wakefield should treat any unsolicited follow-up communication referencing the breach with caution and verify its legitimacy directly with the company before responding or clicking any links.
Cushman & Wakefield has not publicly disclosed the full technical details of how the unauthorized party first gained access to its network, and the company’s own notification materials do not specify a fully itemized list of every data element involved beyond confirming that names were affected in combination with other personal information. Companies are not always able to disclose every detail of an ongoing security investigation, particularly while remediation and law enforcement coordination are still underway, but affected individuals are nonetheless entitled to understand what protections are being made available and what steps they can take to protect themselves going forward.
Data breach notification laws generally require companies to act within a defined window once they determine that residents of a given state were affected, but the amount of time between the initial intrusion and the mailing of notices can still stretch across several months depending on the complexity of the forensic review. A comprehensive review of exfiltrated files, particularly when a large volume of data is involved, often requires cybersecurity specialists to manually cross-reference file contents against employee and client records before a company can even determine who needs to be notified, let alone what specific information about each person was exposed.
Individuals affected by a breach at a company like Cushman & Wakefield may not immediately grasp the scope of their risk, particularly given the relatively limited detail companies sometimes provide about a specific incident. Consulting with an attorney experienced in data breach litigation can help affected individuals better understand their legal options and any potential compensation available, especially when a company’s own notification materials leave open questions about the full extent of the personal information involved.
When Did This Breach Occur?
Cushman & Wakefield reported that the unauthorized access occurred on or around April 21, 2026, and April 29, 2026, according to the sample notification letter it filed with the California Attorney General’s office. The company’s notification letters to affected individuals are dated August 7, 2026, meaning several months passed between the company becoming aware of the incident and individuals being formally notified. This gap is common in breach investigations, as companies typically need time to determine the scope of an intrusion and identify which individuals were affected before sending legally required notices.
What Information Was Breached?
According to Cushman & Wakefield’s notification letter, the company believes there may have been unauthorized access to affected individuals’ names in combination with certain other personal data elements specific to each individual. The company has not publicly disclosed a specific universal list of every data type involved for all affected individuals. Cushman & Wakefield says it has seen no indication that any of the accessed information has actually been viewed or misused by an unauthorized party, though it is offering complimentary identity protection services to those affected out of caution.
What You Can Do
Cushman & Wakefield is offering affected individuals 24 months of complimentary identity protection services through Experian IdentityWorks, including credit monitoring and identity restoration support. If you received a notification letter, consider taking the following steps:
- Enroll in the identity protection services offered in your notification letter before the stated deadline
- Monitor your financial accounts and credit reports regularly for signs of suspicious activity
- Be cautious of unsolicited communications referencing the breach, and verify legitimacy directly with the company before responding
- Consider placing a fraud alert or credit freeze with the three major credit bureaus
- Change passwords or security credentials for any accounts that may have used elements of the exposed personal data
File a Data Breach Lawsuit Against Cushman & Wakefield
If you were affected by the Cushman & Wakefield data breach, you may be entitled to compensation. Companies that collect sensitive personal information have a legal responsibility to keep it secure, and a class action lawsuit can help hold Cushman & Wakefield accountable while helping affected individuals recover for any harm they experienced.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.