News Room
16
Share
RansomHub Extorts Christie’s Following High-Profile Theft of Elite Collector Data
highThreat Intelligence

RansomHub Extorts Christie’s Following High-Profile Theft of Elite Collector Data

RansomHub has officially listed Christie's on its leak site, claiming the theft of sensitive personal data for 500,000 global clients after a disruptive May cyberattack on the auction house.

23 July 2026Last updated 20 August 20265 min readMandiant Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2024-1709
Source:
Mandiant Intelligence
Read Time:
5 min

Executive Summary

Following a ten-day technological 'blackout' during its critical spring auction season, Christie’s auction house has been formally listed on the RansomHub extortion portal. The threat actors claim to have exfiltrated over 2 gigabytes of sensitive personal data, including the identities, nationalities, and government ID details of nearly 500,000 high-net-worth collectors. This incident marks a significant escalation for RansomHub, a group that has rapidly filled the vacuum left by the law enforcement takedowns of ALPHV/BlackCat and LockBit earlier this year.

Threat Analysis

RansomHub operates as a highly aggressive Ransomware-as-a-Service (RaaS) model, distinguished by its 'affiliate-first' approach where partners retain up to 90% of the ransom proceeds. In the case of Christie’s, the group is employing a classic double-extortion strategy. By refusing to pay, Christie’s faces the public release of 'Category 1' data—private details of its most elite clients. The group's choice of timing, hitting during major New York auctions, demonstrates a sophisticated understanding of their victim's operational and reputational pressure points.

Technical Details

Technical analysis of RansomHub’s recent campaigns reveals the use of a custom encryptor written in Golang (Go), which allows for efficient cross-platform execution across Windows and Linux (ESXi) environments. Initial access is frequently achieved through the exploitation of edge vulnerabilities—such as those found in ConnectWise ScreenConnect (CVE-2024-1709)—or through valid credential abuse facilitated by Initial Access Brokers (IABs). Once established, RansomHub affiliates utilize 'Living off the Land' (LotL) techniques, leveraging PowerShell and legitimate remote management tools like AnyDesk to evade traditional EDR signatures during the data staging phase. In the Christie's incident, the attackers specifically targeted administrative accounts to bypass standard multi-factor authentication (MFA) protocols.

Attribution Assessment

Encrygma analysts, in alignment with findings from Mandiant and Unit 42, assess with high confidence that RansomHub is a successor or evolution of the 'Knight' ransomware operation. The underlying code shares significant similarities with Knight and the earlier Cyclops variants. Furthermore, the group's 'No-Target' list (covering the CIS, China, and North Korea) and its communication patterns suggest the core developers are likely operating out of a Russian-speaking jurisdiction, potentially incorporating displaced affiliates from the defunct ALPHV/BlackCat infrastructure.

Implications

The potential leak of collector data represents a profound reputational and legal threat. Beyond the immediate risk of identity theft for Christie’s clients, the exposure of art purchase histories and wealth profiles creates a secondary physical security risk for these individuals. Legally, Christie’s faces significant exposure under the EU’s GDPR and the UK’s Data Protection Act, where failure to secure personal data can result in fines up to 4% of annual global turnover. This breach serves as a stark warning to the luxury goods sector regarding the high value placed on client privacy by modern extortionists.

Recommendations

Encrygma recommends that organizations in the high-value asset sector shift from a reactive to a proactive defensive posture. Key steps include: 1. Implementing phishing-resistant MFA across all external-facing services. 2. Conducting urgent audits of all remote monitoring and management (RMM) tools to identify unauthorized persistence. 3. Deploying advanced data loss prevention (DLP) solutions to alert on large-scale exfiltration of database files. 4. Enhancing segmentation between corporate IT and client-facing web infrastructures. 5. Regularly performing threat hunting exercises focused on Golang-based binaries and unusual PowerShell execution patterns.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo