Christie's
Disclosed May 28, 20242 years ago45,798 affectedConfirmed
RansomHub attack on Christie's exposes ID data of 45,798 clients
Auction house Christie's disclosed a data breach after a May 2024 ransomware attack that took its website offline during its spring sales; RansomHub claimed the attack. RansomHub claimed to hold identity document data on 500,000 clients; Christie's later reported 45,798 affected individuals.
What is known
| People affected | 45,798 (as reported by the organization) |
|---|---|
| Disclosed | May 28, 2024 |
| Discovered | May 9, 2024 |
| Happened | May 8, 2024 |
| Attack | Ransomware |
| Data exposed | Names, Government IDs, Dates of birth |
| Sector | Retail · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Christie'soag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: Christie'satg.wa.gov · Official notice | Official notice |
| Oregon DOJ breach notice: Christie'sjustice.oregon.gov · Official notice | Official notice |
| Christie disclosed a data breach after a RansomHub attacksecurityaffairs.com · News | News |
| Christie's data breach impacted 45,798 individualssecurityaffairs.com · News | News |
| Vermont Attorney General: 2024-06-07 Christie’s Data Breach Notice to Consumersago.vermont.gov · Official notice | Official notice |
| Indiana Attorney General 2024 data breach report: Christie'sin.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | May 28, 2024 | 45,798 |
| California AGresidents of CA | Jun 7, 2024 | |
| Washington AGresidents of WA | Jun 7, 2024 | 985 |
| Oregon DOJresidents of OR | Jun 7, 2024 | 45,798 |
| Vermont AGresidents of VT | Jun 7, 2024 | |
| Indiana AGresidents of IN | Jun 7, 2024 | 363 |
Other breaches at Christie's
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Mar 24, 2017Mar 24, 20179 years ago | Mar 24, 20179 years ago | Not stated | Retail | Confirmed | Unknown |
History of this record
- 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Reportdec-2024.pdf · backfill source
- 2026-09-25 · source: empty to https://ago.vermont.gov/document/2024-06-07-christies-data-breach-notice-consumers · backfill source
- 2026-09-25 · sector: other to retail · seed source
- 2026-09-25 · data_types: [] to ["names","government-id","dob"] · seed source
- 2026-09-25 · records_basis: empty to organization · seed source
- 2026-09-25 · records: empty to 45798 · seed source
- 2026-09-25 · disclosed: 2024-06-07 to 2024-05-28 · seed source
- 2026-09-25 · summary: empty to Auction house Christie's disclosed a data breach after a May 2024 ransomware attack that took its website offline during its spring sales; RansomHub claimed the attack. RansomHub claimed to hold identity document data on 500,000 clients; Ch · seed source
- 2026-09-25 · title: empty to RansomHub attack on Christie's exposes ID data of 45,798 clients · seed source
- 2026-09-25 · attack: unknown to ransomware · backfill source
- 2026-09-25 · discovered: empty to 2024-05-09 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.