INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters and Qilin Target Real Estate Giant via Vishing
| 2026-05-05 13:34 DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A data breach occurred at Cushman & Wakefield on May 1, 2026, when two cybercrime groups, ShinyHunters and Qilin, claimed responsibility for the attack. The incident was reportedly a result of vishing (voice phishing), with an employee being socially engineered into divulging sensitive information. As a result, over 500,000 Salesforce records containing personally identifiable information (PII) were stolen. Cushman & Wakefield activated its response protocols and engaged third-party expert advisors to support the investigation. The attack was later confirmed by ShinyHunters, which claimed it had stolen the data before setting a May 6 deadline for C&W to make contact or risk further leakage.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Tactical Metrics
Intelligence Sources
The Register - CSO
2026-05-05