Sotheby’s International: Luxury real estate firm hit by cyber security attack

Sotheby’s International: Luxury real estate firm hit by cyber security attack

Sotheby’s International Investigates Cybersecurity Incident Involving Client Data

Luxury real estate firm Sotheby’s International is probing a cybersecurity incident involving unauthorized access to a third-party marketing platform containing client contact information. The breach, discovered recently, targeted a system used to store names, addresses, email addresses, and phone numbers.

In a statement, Sotheby’s confirmed that no financial transaction data, property documentation, or email exchanges were compromised. The company acted swiftly to contain the incident and engaged forensic investigators to assess the scope. While the attacker claimed to have accessed 1.6 million contacts, Sotheby’s refuted this, stating the figure included duplicate entries in its database.

New Zealand managing director Mark Harris acknowledged the breach, emphasizing the firm’s commitment to transparency and client trust. He noted that while most exposed data was limited to basic contact details, some sensitive information stored in open-text notes fields may have been accessed. Affected individuals will be contacted directly.

Sotheby’s continues to work with cybersecurity specialists to secure client data and will provide updates as the investigation progresses.

Source: https://www.rnz.co.nz/news/crime-and-justice/1118363/luxury-real-estate-firm-hit-by-cyber-security-attack

Sotheby’s International TPRM report: https://www.rankiteo.com/company/sothebysrealty

"id": "sot1787632135",
"linkid": "sothebysrealty",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1.6 million contacts (claimed '
                                              'by attacker, includes '
                                              'duplicates)',
                        'industry': 'Real Estate',
                        'location': 'Global (New Zealand managing director '
                                    'mentioned)',
                        'name': 'Sotheby’s International',
                        'type': 'Luxury real estate firm'}],
 'attack_vector': 'Unauthorized access to third-party marketing platform',
 'customer_advisories': 'Affected individuals will be contacted directly',
 'data_breach': {'number_of_records_exposed': '1.6 million (claimed, includes '
                                              'duplicates)',
                 'personally_identifiable_information': 'Names, addresses, '
                                                        'email addresses, '
                                                        'phone numbers',
                 'sensitivity_of_data': 'Low to moderate (basic contact '
                                        'details, some sensitive notes)',
                 'type_of_data_compromised': 'Client contact information, '
                                             'open-text notes fields'},
 'description': 'Luxury real estate firm Sotheby’s International is '
                'investigating a cybersecurity incident involving unauthorized '
                'access to a third-party marketing platform containing client '
                'contact information. The breach targeted a system used to '
                'store names, addresses, email addresses, and phone numbers. '
                'No financial transaction data, property documentation, or '
                'email exchanges were compromised. The attacker claimed to '
                'have accessed 1.6 million contacts, but Sotheby’s refuted '
                'this, stating the figure included duplicate entries.',
 'impact': {'data_compromised': 'Client contact information (names, addresses, '
                                'email addresses, phone numbers), some '
                                'sensitive information in open-text notes '
                                'fields',
            'identity_theft_risk': 'Potential',
            'systems_affected': 'Third-party marketing platform'},
 'investigation_status': 'Ongoing',
 'references': [{'source': 'Sotheby’s International Statement'}],
 'response': {'communication_strategy': 'Direct contact with affected '
                                        'individuals, public statement',
              'containment_measures': 'Swift action to contain the incident',
              'incident_response_plan_activated': 'Yes',
              'third_party_assistance': 'Forensic investigators, cybersecurity '
                                        'specialists'},
 'title': 'Sotheby’s International Cybersecurity Incident Involving Client '
          'Data',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.