Company Details
liveauctioneers
55
4,303
513
liveauctioneers.com
0
LIV_2486005
In-progress

LiveAuctioneers Company CyberSecurity Posture
liveauctioneers.comLiveAuctioneers is the leading online auction marketplace for one-of-a-kind items, rare collectibles and coveted goods. LiveAuctioneers is part of Auction Technology Group plc (LON:ATG), the operator of the world’s leading marketplaces and auction services for online auctions, seamlessly connecting bidders to an underexplored world of secondary goods that have been curated by thousands of trusted auctioneer experts.
Company Details
liveauctioneers
55
4,303
513
liveauctioneers.com
0
LIV_2486005
In-progress
Between 700 and 749

LiveAuctioneers Global Score (TPRM)XXXX

Description: The Washington State Office of the Attorney General reported a data breach involving LiveAuctioneers affecting 38,523 residents. The breach occurred on June 19, 2020, due to a cyberattack that exploited a third-party software solution, leading to the exposure of user names, email addresses, and hashed passwords. The breach was discovered on July 11, 2020, and notification was provided on September 3, 2020.
Description: The California Office of the Attorney General reported a data breach involving LiveAuctioneers, LLC on September 10, 2020. The breach occurred on June 19, 2020, and involved unauthorized access to user account information, including names, email addresses, mailing addresses, phone numbers, visit history, and decrypted passwords, although complete payment card numbers were not accessed.


No incidents recorded for LiveAuctioneers in 2025.
No incidents recorded for LiveAuctioneers in 2025.
No incidents recorded for LiveAuctioneers in 2025.
LiveAuctioneers cyber incidents detection timeline including parent company and subsidiaries

LiveAuctioneers is the leading online auction marketplace for one-of-a-kind items, rare collectibles and coveted goods. LiveAuctioneers is part of Auction Technology Group plc (LON:ATG), the operator of the world’s leading marketplaces and auction services for online auctions, seamlessly connecting bidders to an underexplored world of secondary goods that have been curated by thousands of trusted auctioneer experts.


IndiaMART is India's largest online B2B marketplace, connecting buyers with suppliers across a wide array of industries. IndiaMART provides a platform for Small & Medium Enterprises (SMEs), large enterprises, and individual buyers, helping them access diverse portfolios of quality products. Since
Sohu.com Inc. (NASDAQ: SOHU) is China's premier online brand and indispensable to the daily life of millions of Chinese, providing a network of web properties and community based/web 2.0 products which offer the vast Sohu user community a broad array of choices regarding information, entertainment a
More people find jobs on Indeed than anywhere else. Indeed is the #1 job site in the world (Comscore, Total Visits, March 2024) and allows job seekers to search millions of jobs in more than 60 countries and 28 languages. Indeed has more than 580 million Job Seeker Profiles. Every day, job seekers u

We are a technology company that unlocks access to energy for the benefit of all. As innovators, that’s been our mission for nearly a century. Today, we face a global imperative to create a future with more energy, but less carbon. Our diverse, innovative change makers are focused on going further i

As a leading internet technology company based in China, NetEase, Inc. (NASDAQ: NTES and HKEX:9999, "NetEase") provides premium online services centered around content creation. With extensive offerings across its expanding gaming ecosystem, NetEase develops and operates some of China's most popula
OYO is a global platform that aims to empower entrepreneurs and small businesses with hotels and homes by providing full-stack technology products and services that aims to increase revenue and ease operations; bringing easy-to-book, affordable, and trusted accommodation to customers around the worl
Jumia (NYSE :JMIA) is a leading e-commerce platform in Africa. It is built around a marketplace, Jumia Logistics, and JumiaPay. The marketplace helps millions of consumers and sellers to connect and transact. Jumia Logistics enables the delivery of millions of packages through our network of local p

Avnet is a global electronic components distributor with extensive design, product, marketing and supply chain expertise for customers and suppliers at every stage of the product lifecycle. For the past 100 years, Avnet has helped its customers and suppliers around the world realize the transformati

The mission of the Death Star is to keep the local systems "in line". As we have recently dissolved our Board of Directors, there is little resistance to our larger goal of universal domination. Our Stormtroopers are excellent shots and operate with our Navy, and are fielded like marines - sep
.png)
LiveAuctioneers, an online auction platform headquartered in the United States, has confirmed a security incident after a database containing 3.4 million user...
Antiques marketplace blames breach on data processing partner LiveAuctioneers, an online antiques marketplace, has revealed that it suffered...
LiveAuctioneers has disclosed a data breach after a well-known data breach broker began selling 3.4 million stolen user records on a hacker forum.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of LiveAuctioneers is https://www.liveauctioneers.com.
According to Rankiteo, LiveAuctioneers’s AI-generated cybersecurity score is 714, reflecting their Moderate security posture.
According to Rankiteo, LiveAuctioneers currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, LiveAuctioneers is not certified under SOC 2 Type 1.
According to Rankiteo, LiveAuctioneers does not hold a SOC 2 Type 2 certification.
According to Rankiteo, LiveAuctioneers is not listed as GDPR compliant.
According to Rankiteo, LiveAuctioneers does not currently maintain PCI DSS compliance.
According to Rankiteo, LiveAuctioneers is not compliant with HIPAA regulations.
According to Rankiteo,LiveAuctioneers is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
LiveAuctioneers operates primarily in the Technology, Information and Internet industry.
LiveAuctioneers employs approximately 55 people worldwide.
LiveAuctioneers presently has no subsidiaries across any sectors.
LiveAuctioneers’s official LinkedIn profile has approximately 4,303 followers.
LiveAuctioneers is classified under the NAICS code 513, which corresponds to Others.
Yes, LiveAuctioneers has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/live-auctioneers.
Yes, LiveAuctioneers maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/liveauctioneers.
As of November 28, 2025, Rankiteo reports that LiveAuctioneers has experienced 2 cybersecurity incidents.
LiveAuctioneers has an estimated 12,595 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Title: LiveAuctioneers Data Breach
Description: Unauthorized access to user account information, including names, email addresses, mailing addresses, phone numbers, visit history, and decrypted passwords.
Date Detected: 2020-06-19
Date Publicly Disclosed: 2020-09-10
Type: Data Breach
Attack Vector: Unauthorized Access
Title: LiveAuctioneers Data Breach
Description: The Washington State Office of the Attorney General reported a data breach involving LiveAuctioneers affecting 38,523 residents. The breach occurred on June 19, 2020, due to a cyberattack that exploited a third-party software solution, leading to the exposure of user names, email addresses, and hashed passwords. The breach was discovered on July 11, 2020, and notification was provided on September 3, 2020.
Date Detected: 2020-07-11
Date Publicly Disclosed: 2020-09-03
Type: Data Breach
Attack Vector: Exploitation of third-party software
Vulnerability Exploited: Third-party software vulnerability
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Email addresses, Mailing addresses, Phone numbers, Visit history, Decrypted passwords

Data Compromised: User names, Email addresses, Hashed passwords
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Email Addresses, Mailing Addresses, Phone Numbers, Visit History, Decrypted Passwords, , User Names, Email Addresses, Hashed Passwords and .

Entity Name: LiveAuctioneers, LLC
Entity Type: Company
Industry: Online Auction

Entity Name: LiveAuctioneers
Entity Type: Company
Industry: Online Auction
Customers Affected: 38523

Type of Data Compromised: Names, Email addresses, Mailing addresses, Phone numbers, Visit history, Decrypted passwords
Personally Identifiable Information: namesemail addressesmailing addressesphone numbers

Type of Data Compromised: User names, Email addresses, Hashed passwords
Number of Records Exposed: 38523

Source: California Office of the Attorney General
Date Accessed: 2020-09-10

Source: Washington State Office of the Attorney General
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney GeneralDate Accessed: 2020-09-10, and Source: Washington State Office of the Attorney General.
Most Recent Incident Detected: The most recent incident detected was on 2020-06-19.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2020-09-03.
Most Significant Data Compromised: The most significant data compromised in an incident were names, email addresses, mailing addresses, phone numbers, visit history, decrypted passwords, , User names, Email addresses, Hashed passwords and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were visit history, Email addresses, names, User names, email addresses, decrypted passwords, Hashed passwords, phone numbers and mailing addresses.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 408.0.
Most Recent Source: The most recent source of information about an incident are Washington State Office of the Attorney General and California Office of the Attorney General.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.