Were you recently affected by a data breach?

Cushman & Wakefield Data Breach

Cushman & Wakefield, a global commercial real estate services firm, disclosed that an unauthorized third party accessed its network in April 2026 and exfiltrated certain company files. If you received a notice about this breach, contact Class Action U today to learn about your legal options.

Cushman & Wakefield
Date of Breach: April 21, 2026 and April 29, 2026
CAU logo

Who was affected:

Clients of Cushman & Wakefield

Impacted Data:

Names in combination with certain other personal data elements not fully specified by the company

Cushman & Wakefield, one of the largest commercial real estate services firms in the world, has disclosed that an unauthorized third party gained access to its systems and exfiltrated certain company data. Companies that collect and store sensitive personal information have a responsibility to protect it from unauthorized access, and a breach of this nature can leave affected individuals vulnerable to fraud and identity theft.

Cushman & Wakefield’s Data Breach Investigation

Cushman & Wakefield reported that on April 29, 2026, it became aware of unauthorized access to its network by a third party, who the company determined was able to exfiltrate certain files. Following discovery of the incident, Cushman & Wakefield undertook what it described as a diligent, comprehensive review of the affected data and files to determine which individuals were impacted and what categories of personal information were involved. That review reportedly confirmed that certain personal data relating to affected individuals was accessed and taken by the unauthorized third party.

In the notification letters Cushman & Wakefield began sending to affected individuals, the company stated it has seen no indication that the accessed information has actually been viewed or misused by the unauthorized party. Out of an abundance of caution, the company chose to notify potentially affected individuals and offer them access to identity protection resources. Cushman & Wakefield says it has since reset system passwords and access credentials, implemented heightened monitoring across its network, and notified law enforcement about the incident.

Breaches involving large commercial and professional services firms are an increasingly common target for cybercriminals, in part because these companies often maintain large repositories of personal and financial data belonging to employees, clients, tenants, and business partners. A single successful intrusion can expose records covering thousands of individuals across many different relationships with the company, which is part of why this type of incident routinely triggers state-mandated notification requirements once an investigation confirms unauthorized access.

Cyberattacks such as this one frequently follow a similar pattern: an outside actor gains unauthorized entry into a company’s network, quietly copies or exfiltrates files before detection, and only then triggers the company’s incident-response and legal-notification obligations. The gap between initial intrusion and public notification can leave affected individuals unaware for weeks or months that their information may be circulating outside the company’s control, which is one reason regulators require prompt notice once an investigation is far enough along to identify who was affected.

When names are exposed in combination with other personal identifiers, affected individuals can face an elevated risk of follow-up phishing attempts, where scammers use breach notifications as a pretext to send fraudulent emails or texts requesting additional personal or financial details. Consumers who receive a notification letter from Cushman & Wakefield should treat any unsolicited follow-up communication referencing the breach with caution and verify its legitimacy directly with the company before responding or clicking any links.

Cushman & Wakefield has not publicly disclosed the full technical details of how the unauthorized party first gained access to its network, and the company’s own notification materials do not specify a fully itemized list of every data element involved beyond confirming that names were affected in combination with other personal information. Companies are not always able to disclose every detail of an ongoing security investigation, particularly while remediation and law enforcement coordination are still underway, but affected individuals are nonetheless entitled to understand what protections are being made available and what steps they can take to protect themselves going forward.

Data breach notification laws generally require companies to act within a defined window once they determine that residents of a given state were affected, but the amount of time between the initial intrusion and the mailing of notices can still stretch across several months depending on the complexity of the forensic review. A comprehensive review of exfiltrated files, particularly when a large volume of data is involved, often requires cybersecurity specialists to manually cross-reference file contents against employee and client records before a company can even determine who needs to be notified, let alone what specific information about each person was exposed.

Individuals affected by a breach at a company like Cushman & Wakefield may not immediately grasp the scope of their risk, particularly given the relatively limited detail companies sometimes provide about a specific incident. Consulting with an attorney experienced in data breach litigation can help affected individuals better understand their legal options and any potential compensation available, especially when a company’s own notification materials leave open questions about the full extent of the personal information involved.

When Did This Breach Occur?

Cushman & Wakefield reported that the unauthorized access occurred on or around April 21, 2026, and April 29, 2026, according to the sample notification letter it filed with the California Attorney General’s office. The company’s notification letters to affected individuals are dated August 7, 2026, meaning several months passed between the company becoming aware of the incident and individuals being formally notified. This gap is common in breach investigations, as companies typically need time to determine the scope of an intrusion and identify which individuals were affected before sending legally required notices.

What Information Was Breached?

According to Cushman & Wakefield’s notification letter, the company believes there may have been unauthorized access to affected individuals’ names in combination with certain other personal data elements specific to each individual. The company has not publicly disclosed a specific universal list of every data type involved for all affected individuals. Cushman & Wakefield says it has seen no indication that any of the accessed information has actually been viewed or misused by an unauthorized party, though it is offering complimentary identity protection services to those affected out of caution.

What You Can Do

Cushman & Wakefield is offering affected individuals 24 months of complimentary identity protection services through Experian IdentityWorks, including credit monitoring and identity restoration support. If you received a notification letter, consider taking the following steps:

  • Enroll in the identity protection services offered in your notification letter before the stated deadline
  • Monitor your financial accounts and credit reports regularly for signs of suspicious activity
  • Be cautious of unsolicited communications referencing the breach, and verify legitimacy directly with the company before responding
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus
  • Change passwords or security credentials for any accounts that may have used elements of the exposed personal data

File a Data Breach Lawsuit Against Cushman & Wakefield

If you were affected by the Cushman & Wakefield data breach, you may be entitled to compensation. Companies that collect sensitive personal information have a legal responsibility to keep it secure, and a class action lawsuit can help hold Cushman & Wakefield accountable while helping affected individuals recover for any harm they experienced.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Suspicious activity identified July 9, 2026
Date of Breach: Notification sent August 2026
Date of Breach: December 2, 2025 to December 18, 2025 (discovered May 26, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.