CSIDB logo
Incident

Christie's

Incident posture

Attack window
May 2024
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-31 12:06

Linked entities

Victim
Christie's
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The auction house experienced a cyberattack disrupting its website, forcing reliance on a temporary platform without online bidding capabilities during major sales events. Despite the outage, critical auctions proceeded via in-person and phone participation, accounting for nearly half its annual revenue. This incident followed a prior breach less than a year earlier that exposed sensitive client artwork location data. The website remained inaccessible, and company officials provided limited updates while assuring clients of ongoing sales operations.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 9, 2024, Christie’s auction house experienced a cyberattack that forced its official website offline, described by the company as a "technology security issue." The incident occurred days before the start of Christie’s spring auctions, which represent nearly half of its annual revenue. By May 12, the website remained inaccessible, replaced initially by a temporary landing page apologizing for the disruption and promising client updates. The attack disrupted online bidding and registration systems critical for the upcoming marquee sales, which featured high-value artworks like Andy Warhol’s $30 million "Flowers" and Barbara Kruger’s $600,000 conceptual piece. Christie’s employees assured clients visiting its Rockefeller Center galleries that website restoration was "imminent," but the issue persisted through the weekend.

On May 11, CEO Guillaume Cerruti confirmed via email that eight auctions would proceed as scheduled with in-person and phone bidding, though the rare watches sale was postponed to May 14. Christie’s deployed a secondary temporary website using free design tool Shorthand, allowing catalog browsing but not online bidding or registration. The attack marked Christie’s second cybersecurity breach in under a year, following an August 2023 incident where a German firm exposed a data leak revealing artwork locations of wealthy collectors. The spring auctions proceeded amid uncertainty, with artworks totaling $840 million in high estimates on display. No details were provided about the attack’s origin, data compromise, or restoration timeline for full website functionality, and the company did not clarify how online auction components would be reinstated.

Sources

Sources available to members: 1 source.

CSIDB