HackingData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
SOTHEBY'S
bd_9d993dd442d3ccba · schema v1 · pii pii-v1
Full breach record for SOTHEBY'S →Sotheby’s notified the New Hampshire Attorney General on October 15, 2025, of a data event affecting one NH resident. On July 24, 2025, Sotheby’s became aware that data appeared to have been removed by an unknown actor. The affected data included the resident's name and Social Security number. Sotheby’s engaged third-party specialists, worked with federal law enforcement, and offered 12 months of credit monitoring via TransUnion.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4bd73b04199aa29bVermont State AGfiled 2025-10-15Verified
- bd_84da0953b8865c3dMaine State AGfiled 2025-10-15Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sothebys-20251015.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 15, 2025
- Raw hash
- 3fb1c643742008cbec07f1fbf6c458f363de15c63b31396d29caac1b5d632c14
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- SOTHEBY'Snorm: sotheby s
- Domain
- sothebys.com
Incident
- Discovered
- Jul 24, 2025
- Materiality determined
- —
- Notification sent
- Oct 15, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified Office of the New Hampshire Attorney GeneralNotified three major credit reporting agencies (Equifax, Experian, TransUnion)
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.