EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware/christies-ransomware-attack-2024
094/430

File EL-0337HighResolvedRansomware / Ransomware with Data Exfiltration

Christie's Ransomware Attack

Also filed as Christie's Auction House Hack · Christie's Data Breach

Christie's, the world-renowned auction house founded in 1766, suffered a ransomware attack in May 2024 just days before its major spring auction season. The attack forced its website offline, disrupted online bidding, and resulted in the theft of sensitive client data including passports and financial information of ultra-high-net-worth individuals.

  • #art-market
  • #auction-house
  • #ransomware
  • #high-net-worth
  • #luxury
  • #client-data
  • #cultural
Notoriety8/10
Event
9 May 2024
Disclosed
12 May 2024
Target
Christie's
Scale
500K people
Status
Resolved

01Summary

On May 9, 2024, Christie's was hit by a ransomware attack that crippled its digital operations days before the prestigious spring auction season. The attack took Christie's website offline, disabled online bidding platforms, and forced the company to delay several major auctions. The stolen data included client names, addresses, passport copies, bank account details, and provenance records for high-value artworks. The breach was particularly damaging given Christie's handling of ultra-high-net-worth clients.

02Background

Christie's is one of the world's oldest and largest auction houses, established in 1766 in London. Annual sales exceeding $7 billion. Client base includes the world's wealthiest individuals and institutions.

03Key revelations

  1. 01Ransomware attack timed to disrupt Christie's critical spring auction season
  2. 02Ultra-high-net-worth client data including passport copies stolen
  3. 03Auction house forced to delay multiple major sales

04Technical analysis

The ransomware group gained access through compromised third-party vendor credentials. They spent approximately two weeks mapping the network and exfiltrating data before deploying ransomware.

Attack vector
Compromised third-party vendor credentials
Attack method
Ransomware encryption with data exfiltration (double extortion)
Initial access
Third-party vendor account compromise
Exfiltration
Data exfiltration during extended network reconnaissance before ransomware deployment

05Threat actor

Professional ransomware group with focus on hospitality sector. Demonstrated patience in network reconnaissance before deploying encryption across all systems including backups.

Attribution sources

  • BleepingComputer
  • Media reports

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Client names
  • Addresses
  • Phone numbers
  • Passport copies
  • Bank account details
  • Art collection records
  • Provenance documentation
  • Bidding histories

08Financial damage

Sales disruption during critical spring auction season. Reputational damage with ultra-high-net-worth client base.

09Timeline

  1. 2024-05-09Ransomware attack detected; website taken offline
  2. 2024-05-12Spring auctions disrupted
  3. 2024-05-15Ransomware group claims responsibility
  4. 2024-05-20Client data posted on leak site

10Reaction and fallout

Public reaction

Significant concern in the art world about client privacy and data security. Ultra-wealthy collectors expressed alarm about exposure of their art holdings.

Political impact

Discussions about cybersecurity requirements for major auction houses handling sensitive client data.

11Legal

UK ICO investigation into data protection practices.

Civil lawsuits

  • Potential lawsuits from affected high-net-worth clients

12Aftermath

Policy changes

  • Enhanced data protection requirements for art market participants

Security improvements

  • Complete IT security overhaul
  • Enhanced third-party vendor security reviews

13Significance and legacy

Significance

Demonstrated that even the most prestigious cultural institutions with the wealthiest clientele are vulnerable to ransomware.

Legacy

Sent shockwaves through the art world, leading to industry-wide reassessment of cybersecurity.

14Disclosure and media

Authentication
Breach notification and media coverage

Publishing organisations

  • BleepingComputer

15Field notes

  1. 01The attack occurred just days before Christie's major spring auction of a $200M+ art collection
  2. 02Some clients withdrew from auctions due to privacy concerns

16Resolution

Website and systems restored over several weeks. Client notification completed.

17Sources

References

  1. [1]BBC News: Christie's ransomware attack
  2. [2]The Art Newspaper: Christie's cyberattack
  3. [3]BleepingComputer: Christie's hack
Fact sheetEL-0337

Dates

Event
9 May 2024
Started
9 May 2024
Duration
41 days
Discovered
9 May 2024
Disclosed
12 May 2024
Ongoing
No

Target

Organisation
Christie's International plc
Type
Corporation
Sector
Art / Auction House / Luxury
Country
United Kingdom

Actor

Type
Criminal Gang
Motivation
Financial gain through ransomware extortion of a prestigious auction house and theft of sensitive client data of ultra-high-net-worth individuals.
Attribution
Low
Arrested
No
Convicted
No

Data

People
500,000
Records
500,000
Sensitivity
Critical
Published
Yes
Sold (dark web)
No

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.