01Summary
The attack encrypted Tietoevry's cloud platforms hosting payroll, HR, and ERP systems for thousands of Nordic organizations. Swedish grocery chains Coop and ICA unable to process payments. Hundreds of companies unable to process employee payroll. Government agencies and banks disrupted. Most economically impactful ransomware attack in history for a single country.
02Background
Christie's is one of the world's oldest and largest auction houses, established in 1766 in London. Annual sales exceeding $7 billion. Client base includes the world's wealthiest individuals and institutions.
03Key revelations
- 01Single IT provider attack paralyzed Swedish economy
- 02Grocery stores nationwide unable to process payments
- 03Hundreds of companies unable to run payroll
04Technical analysis
The ransomware group gained access through compromised third-party vendor credentials. They spent approximately two weeks mapping the network and exfiltrating data before deploying ransomware.
- Attack vector
- Compromised VPN credentials, lateral movement across cloud infrastructure
- Attack method
- Ransomware encryption with data exfiltration (double extortion)
- Initial access
- Third-party vendor account compromise
- Exfiltration
- Data exfiltration during extended network reconnaissance before ransomware deployment
05Threat actor
Professional ransomware group with focus on hospitality sector. Demonstrated patience in network reconnaissance before deploying encryption across all systems including backups.
Attribution sources
- BleepingComputer
- Media reports
06Victims and impact
Countries affected
- Finland
- Sweden
- Norway
07Data exposed
Data types
- Payroll data
- Employee PII
- ERP data
- HR records
- Financial data
08Financial damage
Sales disruption during critical spring auction season. Reputational damage with ultra-high-net-worth client base.
09Timeline
- 2024-01-19Attack detected
- 2024-01-20Sweden paralyzed
- 2024-01-22Emergency government meeting
- 2024-03-01Services restored
10Reaction and fallout
Public reaction
Significant concern in the art world about client privacy and data security. Ultra-wealthy collectors expressed alarm about exposure of their art holdings.
Political impact
Discussions about cybersecurity requirements for major auction houses handling sensitive client data.
11Legal
UK ICO investigation into data protection practices.
Civil lawsuits
- Potential lawsuits from affected high-net-worth clients
12Aftermath
Policy changes
- Enhanced data protection requirements for art market participants
Security improvements
- Complete IT security overhaul
- Enhanced third-party vendor security reviews
13Significance and legacy
Significance
Demonstrated that even the most prestigious cultural institutions with the wealthiest clientele are vulnerable to ransomware.
Legacy
Sent shockwaves through the art world, leading to industry-wide reassessment of cybersecurity.
14Disclosure and media
- Authentication
- Breach notification and media coverage
Publishing organisations
- BleepingComputer
15Field notes
- 01The attack occurred just days before Christie's major spring auction of a $200M+ art collection
- 02Some clients withdrew from auctions due to privacy concerns
16Resolution
Systems restored over 4-6 weeks. Akira group continues operations.
17Sources
References
- [1]BleepingComputer: Tietoevry hack
- [2]BBC: Sweden disrupted by ransomware









