CHRISTIE’S WEBSITE BREACH 2
Christie’s Website Breach
Christie’s is a world-leading art and luxury business. Renowned and trusted for its live and
online auctions, as well as its bespoke private sales. Their website was set to have an art auction
that was projected to sell as much as $840 million worth of art. They ended up having a cyber-
attack on May 9, 2024. Days before the big art auction was set to take place. The auction house
said that it had a "technology security issue" a few days prior to the auction, which caused its
website to go down. On Thursday night, a few art advisors and collectors became aware of the
issue. By morning, users were being redirected by the website to a temporary page hosted on a
domain other than its own. It stated, "We are sorry that our website is not available at this time."
"We apologize for any inconvenience and are working to resolve this as soon as possible. “A
representative for Christie's, Edward Lewine, stated that a security breach had impacted a few of
the business's systems, including its website. In a statement, he stated, "We are taking all
necessary steps to manage this matter, with the engagement of a team of additional technology
experts. “As appropriate, we will provide our clients additional updates are available.” (Small,
2024) This is not the first time Christie’s has been hit by a cyberattack, with a data breach
reported last August that impacted images of artwork uploaded by customers for review. The
attack revealed the exact location of where the photos were taken.
Extent and Scope
After being taken offline by a cyberattack on May 9, Christie's is attempting to regain control of
its website. All of Christie's live auctions will go forward, the company has said, with bids being
accepted in-person, over the phone, and online through Christie's Live. The auction firm quickly
set up a temporary website with the promise of providing “further updates to our clients as
appropriate.” A second apology and a link to a makeshift website that was swiftly put together
CHRISTIE’S WEBSITE BREACH 3
on the open-source Shorthand platform to enable people to peruse the works up for sale but not
place bids were substituted for the previous message on May 11. The hack may cause clients to
lose faith in Christie's ability to safeguard sensitive customer information, which is concerning
for the company, but it is not anticipated to have a significant negative impact on sales as many
agreements are negotiated in the days, weeks, and even minutes leading up to an auction, with
affluent buyers frequently preferring to view the pieces in person. (News Desk, 2024)
Root Cause
The cyberattack caused Christie's to postpone their Michael Schumacher watch auction, and as of
Tuesday, May 14, the website is still down. Christie's has not yet disclosed the precise cause of
their computer system failure. The incident was described as a "technology security issue," but
no information was provided regarding the nature of the attack or whether any data had been
exposed. Nevertheless, there's a chance that a cyberattack could affect client data, especially
since this is not the first time, they have been attacked in less than a year. Depending on the
extent of the intrusion at Christie’s, it is conceivable that personal banking information,
purchasing history and details of clients’ collections has been stolen, and could be used to
blackmail some of the wealthiest people in the world. However, the extent and cause has not yet
been announced.
Recommendations
One strategy I would recommend helping with this especially since this is the second time it has
happened, is to have a protection system that, by default, refuses access and only allows it when
express permission is obtained. This is commonly referred to as implicit deny operationally,
while it is also known as default deny. In the world of networks, managers frequently decide on a
number of things related to network access. To decide whether or not to grant access, a set of
CHRISTIE’S WEBSITE BREACH 4
rules is frequently used (which is the purpose of a network firewall). The implicit refuse
approach says that access should not be given in a case where any of the other rules do not apply.
Stated differently, access should not be allowed if there is no rule that permits it. Situations
involving both authorization and access are covered by implicit refuse. Complete mediation is
another way to help prevent this, since it checks all access requests for permissions. (Evatt, 2024)
Multiple layers of defense should be used, and it seems like Christie’s is lacking that for some
reason. Something that needs to be done to determine the cause of the breach is to analyze the
data breach. Suspicious traffic, privileged access, duration of the threat, software and people
involved in the breach, and type of breach (internal and external threats) are the fundamental
aspects of the analysis phase. A significant portion of data breaches are induced by seizing
privileged accounts with privileged authorizations, or internal threats which are over-authorized.
The most efficient way to monitor these accounts and prevent data breaches is to employ
Privileged Access Management solutions. Privileged Access Management (PAM) solutions offer
full supervision over privileged account access data and ensure that you have full control over all
movements within your IT infrastructure. (Kron)
CHRISTIE’S WEBSITE BREACH 5
References
Desk, N. (2024, May 13). Christie’s struggles to recover from cyberattack ahead of Spring sales.
Artforum. https://www.artforum.com/news/christies-struggles-to-recover-from-
cyberattack-ahead-spring-sales-553999/
Evatt, D. (2024). Web Security. McGraw-Hill Create.
https://bookshelf.vitalsource.com/books/9781307623215
7 basic steps to identify a data breach: Kron. krontech.com. (n.d.). https://krontech.com/7-basic-
steps-to-identify-a-data-breach
Small, Z. (2024, May 10). Christie’s website is brought down by hackers days before $840
million auctions. The New York Times.
https://www.nytimes.com/2024/05/10/arts/design/christies-cyberattack-website.html
Powered by TCPDF (www.tcpdf.org)