Sotheby's, a leading international auction house specializing in fine art and luxury items, experienced a significant data breach on July 24, 2025. The company confirmed that threat actors gained unauthorized access to its systems and exfiltrated sensitive data, including full names, Social Security numbers, and financial account information. The breach was detected on July 24, prompting Sotheby's to launch an immediate investigation to determine the scope and nature of the compromised data. The investigation, which lasted approximately two months, involved a thorough review of the stolen information to identify the affected individuals. According to filings with the Maine Attorney General's Office, at least two residents of Maine and two of Rhode Island were directly impacted, though the total number of affected individuals remains undisclosed. Sotheby's has not publicly identified the perpetrators behind the attack, and no ransomware group has claimed responsibility as of the latest reports. The company emphasized its ongoing commitment to cybersecurity, stating that it maintains layered defenses, strict access controls, secure connections, and advanced threat protections. Regular patching, incident response testing, vendor vetting, and workforce training are part of Sotheby's security posture. Despite these measures, the attackers were able to bypass defenses and access sensitive data. In response to the breach, Sotheby's is offering 12 months of credit and identity monitoring services through TransUnion to those affected. The company has pledged to review and enhance its security safeguards to prevent future incidents. Sotheby's has so far only reported the breach to the Maine Attorney General, with no filings found in other state data breach portals at the time of reporting. The incident follows a similar attack on Christie's, another major auction house, which was targeted by ransomware actors the previous year. Sotheby's has previously faced security incidents, including malicious code planted on its website to steal payment information. The breach highlights the ongoing risks faced by high-profile organizations handling sensitive client data, particularly those serving high-net-worth individuals. The financial and reputational impact of the breach is still being assessed, as the company continues to investigate and respond to the incident. Sotheby's has not disclosed whether an extortion demand was made or if any ransom was paid. The breach underscores the importance of robust cybersecurity measures and transparent communication with affected clients in the wake of data theft incidents.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
In mid-October 2025, Sotheby’s publicly disclosed the July breach through media reporting and regulatory notifications. The company said it was notifying affected employees and offering 12 months of identity protection and credit monitoring through TransUnion.
After roughly two months of investigation, Sotheby’s determined that the breach affected employees rather than customers. The stolen information included sensitive personal and financial data such as Social Security numbers.
Sotheby’s detected a cyberattack on July 24, 2025, and began investigating the incident with cybersecurity experts and law enforcement. The attack resulted in unauthorized access to and theft of sensitive data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.