INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters and Qilin Target Real Estate Giant via Vishing

| 2026-05-05 13:34 HIGH LOW DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A data breach was reported by Cushman & Wakefield on May 5, 2026, after two cybercrime groups, ShinyHunters and Qilin, claimed responsibility for attacks on the company. The attack is believed to have stemmed from vishing (voice phishing), with an employee being socially engineered. ShinyHunters allegedly stole over 500,000 Salesforce records containing PII and other internal corporate data, while Qilin's website listing showed C&W as a target but did not detail how it was attacked. The attack is considered limited in scope, and the company has activated incident response protocols to contain the unauthorized activity.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/05/05
ShinyHunters and Qilin separately claimed responsibility for a vishing attack on Cushman & Wakefield, resulting in the theft of over 500,000 Salesforce records containing PII.
data_breach 500,000 Salesforce records
Tactical Metrics
Metrics
data_breach
500,000
Salesforce Records
Intelligence Sources
The Register - Cybercrime 2026-05-05