You might recall that threat actors Ransom House had claimed to have pwned auction house Christie’s a couple of weeks ago. At the time I said this:
It will be interesting to see what happens next as we’re only two days from the end of May. I’m pretty sure that this group will release some sort of data in retaliation for not getting paid. But not paying them is the correct course of action as cybercrime groups cannot be allowed to succeed in terms of extorting money from their victims.
Well we’re in June now and it seems that Ransom House has made good on its threat to release data because it appears that Christie’s didn’t pay up. I say that because a data breach notification from Christie’s has appeared.
On May 9, 2024, we discovered that we were the victim of a cybersecurity incident that impacted some of our systems.
As soon as we became aware of this event, we promptly took steps to secure our environment, launched an investigation, and engaged external cybersecurity experts to assist. We also notified law enforcement and continue supporting their investigation.
The investigation revealed an unauthorized actor accessed some of our systems and certain files stored therein between May 8, 2024, and May 9, 2024, and some files were copied from those systems on May 9, 2024. We conducted a robust review of the files to identify individuals whose information may have been impacted and worked to obtain addresses and notify them as quickly as possible after completing the review on May 30, 2024.
Christie’s claims the data that was swiped by Ransom House hasn’t been misused. Which by the way Ransom House claims that the data in question is full names, addresses, ID document details, and various other sensitive personal information of at least half a million clients of the auction house. But at the same time they’re offering up a free twelve-month subscription for the CyEx Identity Defense Total identity theft and fraud monitoring service. Which means that it’s only a matter of time before that information is used to launch secondary attacks. Which will be cold comfort to those who are affected by this.
Seeing as Christie’s is a British company, I wonder what British authorities are going to do. If they do decide to get involved in this, it might be something worth tuning in for.
Related
This entry was posted on June 9, 2024 at 4:59 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Christie’s Confirms That They Got Pwned By Ransom House
You might recall that threat actors Ransom House had claimed to have pwned auction house Christie’s a couple of weeks ago. At the time I said this:
It will be interesting to see what happens next as we’re only two days from the end of May. I’m pretty sure that this group will release some sort of data in retaliation for not getting paid. But not paying them is the correct course of action as cybercrime groups cannot be allowed to succeed in terms of extorting money from their victims.
Well we’re in June now and it seems that Ransom House has made good on its threat to release data because it appears that Christie’s didn’t pay up. I say that because a data breach notification from Christie’s has appeared.
On May 9, 2024, we discovered that we were the victim of a cybersecurity incident that impacted some of our systems.
As soon as we became aware of this event, we promptly took steps to secure our environment, launched an investigation, and engaged external cybersecurity experts to assist. We also notified law enforcement and continue supporting their investigation.
The investigation revealed an unauthorized actor accessed some of our systems and certain files stored therein between May 8, 2024, and May 9, 2024, and some files were copied from those systems on May 9, 2024. We conducted a robust review of the files to identify individuals whose information may have been impacted and worked to obtain addresses and notify them as quickly as possible after completing the review on May 30, 2024.
Christie’s claims the data that was swiped by Ransom House hasn’t been misused. Which by the way Ransom House claims that the data in question is full names, addresses, ID document details, and various other sensitive personal information of at least half a million clients of the auction house. But at the same time they’re offering up a free twelve-month subscription for the CyEx Identity Defense Total identity theft and fraud monitoring service. Which means that it’s only a matter of time before that information is used to launch secondary attacks. Which will be cold comfort to those who are affected by this.
Seeing as Christie’s is a British company, I wonder what British authorities are going to do. If they do decide to get involved in this, it might be something worth tuning in for.
Share this:
Like this:
Related
This entry was posted on June 9, 2024 at 4:59 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.