Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Sotheby's

Sotheby's Vendor Cyber Rating & Cyber Score

sothebys.com

Established in 1744, Sotheby’s is the world’s premier destination for art and luxury. Sotheby’s promotes access to and ownership of exceptional art and luxury objects through auctions and buy-now channels including private sales, e-commerce and retail. Our trusted global marketplace is supported by an industry-leading technology platform and a network of specialists spanning 40 countries and 70 categories which include Contemporary Art, Modern and Impressionist Art, Old Masters, Chinese Works of Art, Jewelry, Watches, Wine and Spirits, and Design, as well as collectible cars and real estate. Sotheby’s believes in the transformative power of art and culture and is committed to making our industries more inclusive, sustainable and


Sotheby's A.I CyberSecurity Scoring

Sotheby's
Company Information
Website:http://www.sothebys.com
Employees number:3,034
Number of followers:292,229
NAICS:7115
Industry Type:Artists and Writers
Homepage:sothebys.com
Sotheby's Risk Score (AI oriented)
Between 550 and 599
logo
Sotheby'sArtists and Writers
Updated:
25/03/2026
581/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Sotheby's Global Score (TPRM)
xxxx
logo
Sotheby'sArtists and Writers
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Sotheby's
Sotheby'sVery Poor
Current Score
581Ca (VERY POOR)
01000
5 incidents
-56 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
601Before Incident
JULY 2026
598Before Incident
JUNE 2026
593Before Incident
MAY 2026
589Before Incident
APRIL 2026
586Before Incident
MARCH 2026
582Before Incident
FEBRUARY 2026
576Before Incident
JANUARY 2026
575Before Incident
DECEMBER 2025
570Before Incident
NOVEMBER 2025
567Before Incident
OCTOBER 2025
617Before Incident
Breach
17 Oct 2025Sotheby's
Sotheby’s

Sotheby’s Data Breach Exposes Sensitive Client Information

561After Incident
CRITICAL-56
SOT1850818101725
Sotheby’s, a globally renowned auction house specializing in art, jewelry, and luxury collectibles, suffered a data breach after hackers gained unauthorized access to its internal systems. The intrusion exposed sensitive personal information of some clients, though the exact scope of compromised data (e.g., financial records, identities, or transaction histories) was not fully disclosed. The breach poses risks of identity theft, fraud, or reputational harm to affected clients, particularly high-net-worth individuals who frequently engage with the auction house. While Sotheby’s confirmed the incident, details on the attack vector (e.g., phishing, exploit of a vulnerability) or whether ransom demands were made remain undisclosed. The breach underscores vulnerabilities in securing high-value client data within the luxury sector, where trust and discretion are paramount. No evidence suggests operational disruption or broader systemic impact beyond the exposed client information.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Sensitive personal informationInternal systems
DATA BREACH
Sensitive personal informationSensitivity Of Data: High
SEPTEMBER 2025
616Before Incident
JULY 2025
666Before Incident
Breach
24 Jul 2025Sotheby's
Sotheby's

Sotheby's Data Breach Exposing Client PII

609After Incident
CRITICAL-57
SOT2593125101625
Sotheby's, a renowned auction house, suffered a data breach in July 2025 when an unknown actor (later identified as the threat group 'm217') exfiltrated sensitive client data from its internal network. The compromised information included personally identifiable details such as names, Social Security numbers, and financial account information, exposing several thousand clients to potential identity theft and financial fraud.The breach was discovered on July 24, 2025, with an internal review confirming the scope of the incident by September 24, 2025. Sotheby's began notifying affected individuals via mail on October 15, 2025, while also disclosing the breach to regulatory bodies like the Maine and Massachusetts Attorneys General. In response, the company secured its systems, engaged law enforcement, and offered 12 months of free credit monitoring (TransUnion Cyberscout) to impacted clients.The incident highlights significant risks to customer privacy, financial security, and reputational damage, as the exposed data could be exploited for fraudulent activities, phishing scams, or unauthorized transactions. The lack of transparency on the exact number of victims further amplifies concerns over the breach’s long-term consequences.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Personally Identifiable Information (PII)NamesSocial Security NumbersFinancial Account InformationBrand Reputation Impact: Potential reputational damage due to exposure of sensitive client dataLegal Liabilities: Disclosure to Maine and Massachusetts Attorney General's offices; potential regulatory scrutinyIdentity Theft Risk: High (due to exposure of SSNs and financial account information)Payment Information Risk: High (financial account information exposed)
DATA BREACH
Personally Identifiable Information (PII)Number Of Records Exposed: Several thousand (exact number not disclosed)Sensitivity Of Data: High (includes SSNs and financial account information)NamesSocial Security NumbersFinancial Account Information
MAY 2025
718Before Incident
Breach
23 May 2025Sotheby's
Sotheby's

Sotheby's Data Breach (2025)

662After Incident
CRITICAL-56
SOT1793317101625
In July 2025, Sotheby's, a globally renowned auction house, suffered a significant data breach orchestrated by a cybercriminal known as 'm217'. The breach involved the unauthorized removal of sensitive personal and financial data, including names, Social Security numbers, and financial account information of an undetermined number of clients. The threat actor publicly claimed responsibility on the dark web as early as May 23, 2025, while Sotheby's completed its internal review by September 24, 2025 and began notifying affected individuals via mail on October 15, 2025. The incident was also formally disclosed to the Maine and Massachusetts Attorney Generals' offices. The exposure of such highly sensitive data poses severe risks, including identity theft, financial fraud, and long-term reputational harm to both the company and its clients. Sotheby's offered 12 months of free credit monitoring to impacted individuals, but the breach’s scale and the nature of the compromised data suggest profound operational and legal repercussions, with law firms already investigating potential class-action lawsuits for compensation.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NameSocial Security numberFinancial account informationBrand Reputation Impact: Potential reputational damage due to exposure of sensitive client dataLegal Liabilities: Potential lawsuits and compensation claims from affected individualsIdentity Theft Risk: High (due to exposure of SSNs and financial data)Payment Information Risk: High (financial account information exposed)
DATA BREACH
Personally Identifiable Information (PII)Financial DataNumber Of Records Exposed: UnknownSensitivity Of Data: High (includes SSNs and financial account information)Data Exfiltration: Yes (confirmed by threat actor's dark web post)NameSocial Security numberFinancial account information
JUNE 2024
765Before Incident
Breach
16 Jun 2024Sotheby's
Sotheby's

Sotheby's Data Breach

705After Incident
CRITICAL-60
SOT1732017101625
Sotheby's, a multinational auction house specializing in fine art and luxury items, confirmed a cyber breach on July 24, where attackers stole sensitive data, including Social Security numbers and financial account information. The company reported the incident to Maine’s Attorney General, disclosing that at least two Maine residents (potentially employees or high-net-worth clients) were affected. While Sotheby’s emphasized its robust security measures—such as regular patching, incident response testing, access controls, and threat protections—the attackers still managed to infiltrate its systems.The breach’s scope remains unclear, including whether the stolen data belonged to staff, clients, or both, and if an extortion demand (e.g., ransomware) was issued. Sotheby’s is offering 12 months of credit and identity monitoring via TransUnion to affected individuals. This incident follows a similar 2024 attack on rival Christie’s, where the RansomHub group stole data but allegedly sold it in a private auction instead of leaking it. Experts suggest such auctions are rare and often a last-ditch effort for monetary gain when victims refuse to pay.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security numbersfinancial account informationBrand Reputation Impact: Potential reputational harm due to breach of high-net-worth client dataIdentity Theft Risk: High (due to exposure of SSNs and financial data)Payment Information Risk: High (financial account information compromised)
DATA BREACH
Social Security numbersfinancial account informationSensitivity Of Data: High (PII and financial data)Data Exfiltration: YesPersonally Identifiable Information: Yes (Social Security numbers)
JUNE 2017
777Before Incident
Breach
16 Jun 2017Sotheby's
Sotheby’s

Sotheby’s Data Breach Incident (2025)

716After Incident
HIGH-61
SOT3762037101725
Sotheby’s, a leading global auction house, experienced a data breach in July 2025 where an unknown threat actor exfiltrated sensitive employee information from its systems. The compromised data included full names, Social Security numbers (SSNs), and financial account details. The breach was detected on July 24, 2025, and a two-month investigation followed to identify the scope and affected individuals. Initially, reports suggested customer data was exposed, but Sotheby’s later clarified that only employee data was impacted. The company is providing affected employees with 12 months of free identity protection and credit monitoring via TransUnion. While no ransomware group has claimed responsibility, the incident underscores Sotheby’s history of cybersecurity vulnerabilities, including past web skimming attacks (2017–2018, 2021) and a 2024 breach at rival Christie’s by RansomHub. The exact number of affected employees remains undisclosed, with only four individuals confirmed in Maine and Rhode Island filings.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Full namesSocial Security numbers (SSNs)Financial account informationBrand Reputation Impact: Potential reputational damage due to exposure of sensitive employee dataIdentity Theft Risk: High (SSNs and financial data exposed)Payment Information Risk: High (financial account information exposed)
DATA BREACH
Personally Identifiable Information (PII)Financial DataSensitivity Of Data: High (SSNs, financial account information)Data Exfiltration: Yes (data removed from Sotheby’s environment)Full namesSocial Security numbers (SSNs)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Sotheby's ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Sotheby's's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Sotheby's's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Sotheby's ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Sotheby's's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?