SOTHEBY'S
ent_019dea410ea976835871b701b65c18d7
Disclosures
3
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SOTHEBY'S
- Normalized
- sotheby s— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300P5BAAMQQ7VL735
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- sothebys.com
Disclosure history (3)newest first
- 🍁Vermont State AGas victim2025-10-15
Sotheby’s notified consumers on October 15, 2025, of a data breach discovered on July 24, 2025, where an unknown actor removed data from its environment. The incident involved personal information including names and government identifiers. Sotheby’s notified federal law enforcement and regulatory authorities, and is offering 12 months of credit monitoring via TransUnion. The investigation was completed by September 24, 2025.
- 🦞Maine State AGas victim2025-10-15
On July 24, 2025, Sotheby's discovered that certain data had been removed from its environment by an unknown external actor. A comprehensive data review was completed around September 24, 2025. The personal information of 2 Maine residents was affected, including names, Social Security numbers, and financial account information. Sotheby's worked with federal law enforcement, notified regulators, and offered 12 months of complimentary credit monitoring via TransUnion.
- ⛰️New Hampshire State AGas victim2025-10-15
Sotheby’s notified the New Hampshire Attorney General on October 15, 2025, of a data event affecting one NH resident. On July 24, 2025, Sotheby’s became aware that data appeared to have been removed by an unknown actor. The affected data included the resident's name and Social Security number. Sotheby’s engaged third-party specialists, worked with federal law enforcement, and offered 12 months of credit monitoring via TransUnion.