News Room
16
Share
RansomHub Threatens Leak of 500,000 Christie’s Records as Auction House Confirms Network Intrusion
criticalThreat Intelligence

RansomHub Threatens Leak of 500,000 Christie’s Records as Auction House Confirms Network Intrusion

RansomHub has listed Christie’s on its dark web portal, claiming theft of sensitive data for half a million global clients. The auction house admits to a breach but denies financial data loss.

30 July 2026Last updated 20 August 20265 min readMandiant Advantage
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2024-24919
Source:
Mandiant Advantage
Read Time:
5 min

Executive Summary

In a significant escalation of cyber-extortion activities within the luxury art sector, the RansomHub cybercriminal syndicate has issued a final ultimatum to Christie’s auction house. Following a disruptive 'technology security incident' in mid-May that coincided with major spring auctions in New York, RansomHub has officially added Christie’s to its extortion portal. The group asserts it has exfiltrated sensitive personal information belonging to approximately 500,000 high-net-worth clients from around the globe. While Christie’s leadership has acknowledged unauthorized access to specific segments of their network, they maintain that there is currently no evidence that financial or transactional records were compromised. This incident underscores the shifting focus of Ransomware-as-a-Service (RaaS) groups toward high-value targets where privacy is a premium commodity.

Threat Analysis

RansomHub is a sophisticated, relatively new player in the RaaS landscape, first appearing in early 2024. The group has quickly established a reputation for aggressive double-extortion tactics, which involve both the encryption of local systems and the exfiltration of data to a public leak site. Their targeting of Christie’s represents a tactical shift toward 'data-only' extortion in scenarios where system encryption might be successfully mitigated by backups, but the threat of public exposure remains a potent lever. By targeting an institution that manages the identities of the world's most affluent individuals, RansomHub is leveraging reputational damage and potential regulatory penalties under the General Data Protection Regulation (GDPR) to compel payment.

Technical Details

Intelligence gathered from recent incident response engagements suggests that RansomHub affiliates often gain initial access through a combination of credential stuffing and the exploitation of edge-device vulnerabilities. Specifically, investigators are looking for links between this breach and recently disclosed zero-day vulnerabilities in remote access solutions, such as the Check Point VPN information disclosure flaw (CVE-2024-24919), which has been actively exploited by various ransomware affiliates for lateral movement and Active Directory harvesting.

Once persistence was established within Christie's network, the actors moved laterally to identify and exfiltrate approximately 500 gigabytes of data. This dataset allegedly includes full names, birth dates, nationalities, and passport or identity document numbers. RansomHub has provided 'proof of life' for the data by publishing screenshots showing database schemas and specific client entries. The group has set a countdown timer on their leak site, threatening to release the full dataset by May 31 if their undisclosed ransom demands are not met.

Attribution Assessment

Cybersecurity researchers at Mandiant and Unit 42 assess with moderate to high confidence that RansomHub is either a rebranding of the Knight ransomware operation or a coalition of experienced affiliates formerly associated with the ALPHV/BlackCat and LockBit syndicates. The group’s infrastructure and malware code show significant similarities to previous Russian-linked operations. RansomHub’s business model is notably affiliate-friendly, offering a 90% commission to those who conduct the intrusions, which has allowed them to attract high-tier talent capable of breaching well-defended networks like those found in the global art market.

Implications

The implications for Christie’s and the broader art market are severe. For Christie's, the breach poses a dual threat of massive regulatory fines and a systemic loss of client trust. The exposure of high-net-worth individuals' data can lead to secondary attacks, including targeted phishing, physical security risks, and identity theft. Furthermore, the timing of the attack—during one of the most critical sales windows of the year—demonstrates that ransomware groups are increasingly timing their activities to maximize operational pressure and financial leverage.

Recommendations

To defend against RansomHub and similar RaaS threats, organizations should implement the following measures:

  1. Phishing-Resistant MFA: Deploy hardware-based multi-factor authentication across all external access points and administrative portals.
  2. Vulnerability Management: Prioritize the immediate patching of edge devices, specifically focusing on VPN and firewall vulnerabilities used for initial access.
  3. Data Loss Prevention (DLP): Implement aggressive DLP rules to monitor and block the unauthorized mass exfiltration of sensitive datasets to known cloud storage providers.
  4. Credential Rotation: Enforce mandatory password resets and certificate rotations following the detection of any suspicious lateral movement within the network.
  5. Legal & Regulatory Readiness: Ensure that incident response plans include specific protocols for notifying international privacy regulators (e.g., UK ICO, EU DPA) within the mandatory 72-hour window following a confirmed breach.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo