Recommended Free Tools
Sotheby’s disclosed that an unknown actor removed data from its systems on July 24, 2025. The breach notice says the information could include names, Social Security numbers and financial-account information. Sotheby’s later said the incident involved certain employee information, not customers; the total number of people affected has not been disclosed.
What happened in the Sotheby’s data breach?
Sotheby’s said data appeared to have been removed from its environment by an unknown actor. A breach notice filed with Maine authorities describes an external system breach and says the company investigated with data-protection and incident-response specialists and cooperated with law enforcement. The notice does not identify how the actor got in or which systems were involved. Maine Attorney General filing; Sotheby’s notice.
Timeline
- July 24, 2025: Sotheby’s said it became aware that data appeared to have been removed by an unknown actor.
- September 24, 2025: The Maine filing lists this as the date Sotheby’s discovered the breach. The notice says the company’s review of potentially affected data was completed around this date. These are separate milestones: discovery and completion of the data review.
- October 15, 2025: Sotheby’s sent written notices to two Maine residents identified as affected.
- October 16–17, 2025: News coverage reported the incident, and Sotheby’s clarified that the affected information related to certain employees rather than customers. BleepingComputer’s report and update.
What information was exposed?
The breach notice says the information varied by person and could include a person’s name, Social Security number and financial-account information. It does not specify that payment-card numbers, account passwords or bank balances were involved, so those should not be assumed. Sotheby’s breach notice.
Were Sotheby’s customers affected?
Sotheby’s later said the incident involved certain employee information. The available public record does not confirm that customer data was exposed, but it also does not provide a complete global impact assessment. The initial coverage’s customer-facing framing should not be treated as confirmation that customers were affected. BleepingComputer.
#1 Best Overall
How many people were affected?
The total number has not been publicly disclosed. Maine’s filing identifies two affected Maine residents; that figure is not a nationwide or worldwide total. Reports referring to notices elsewhere do not establish a definitive total. Maine Attorney General filing.
Was the incident ransomware?
The available reporting does not verify ransomware, system encryption or an extortion demand, and no ransomware group had publicly claimed responsibility in the reporting cited here. The supported description is unauthorized removal of data, not a confirmed ransomware attack. The attacker’s identity and method have not been publicly established. BleepingComputer.
What did Sotheby’s do in response?
Sotheby’s said it investigated the incident, worked with specialists, cooperated with law enforcement and notified affected people as required. Its notice also describes layered defenses, access controls, secure connections, threat protections, patching, incident-response testing, backups, vendor vetting and workforce training. These are the company’s descriptions of its security practices, not independent confirmation of how the breach occurred or was contained.
The Maine filing says affected people were offered 12 months of TransUnion credit monitoring and identity-restoration services. Eligibility and the enrollment deadline should be checked in the individual notice; do not assume the same deadline applies to every recipient. Maine Attorney General filing.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What should someone who received a notice do?
- Confirm the notice is genuine. Use contact information in an official Sotheby’s communication or find the company’s contact details independently; do not rely on links in an unexpected email.
- Use the offered service if eligible. Follow the enrollment instructions and deadline stated in your own notice. Credit monitoring can flag some changes in a credit file, but it cannot prevent every account takeover or detect every misuse of financial information.
- Check financial accounts directly. Review statements and transaction alerts for unauthorized withdrawals, transfers or account changes. Contact your bank or other financial institution immediately if you find suspicious activity.
- Consider a fraud alert or credit freeze. A fraud alert asks businesses to take extra steps to verify identity before extending new credit. A freeze blocks prospective creditors from accessing a credit file unless you lift it; it offers stronger protection against new-account fraud but may add steps when you apply for credit. See the Maine Attorney General’s data-security-breach guidance for consumer context, and contact the credit bureaus directly to place an alert or freeze.
- Review your credit reports. Use the federally authorized service at AnnualCreditReport.com, rather than a link from an unsolicited message.
- Be alert for targeted phishing. Treat unexpected messages about Sotheby’s employment, payroll, auctions, invoices, consignments or account activity cautiously. Do not share passwords, verification codes or payment details in response to an unsolicited request.
- Keep the notice and report suspected identity theft. The notice may be needed to claim the offered service or dispute fraud. Report suspected misuse to the relevant financial institution and, where appropriate, the Federal Trade Commission’s IdentityTheft.gov or your state attorney general.
What is still unknown?
The available public disclosures do not establish the total number affected, whether any customer information was compromised, the attack vector, the attacker’s identity, whether information was misused, or whether an extortion demand was made. They also do not establish whether people outside the United States were affected. No conclusion about those questions should be inferred from the two Maine residents listed in the state filing.
Update — October 17, 2025: Sotheby’s clarified that the incident involved certain employee information rather than customer information. BleepingComputer’s report and update.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




