News: 1715628968

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

'Cyberattack' shutters Christie's website days before $840M art mega-auction

(2024/05/13)


Christie's website remains offline as of Monday after a "technology security issue" shut it down Thursday night – just days before the venerable auction house planned to flog $840 million of art.

As of Friday morning and still today, Christie's redirects visitors to a temporary website, [1]reportedly due to a cyberattack. It's not thought, at the moment, that any customer data has been stolen.

The [2]temporary site right now has the following message on it:

We apologize that our full website is currently offline. We are looking to resolve this as soon as possible and regret any inconvenience.

In a statement to the media, Christie's confirmed "a technology security issue has impacted some of our systems, including our website." The auction house did not immediately respond to The Register 's inquiries on how the digital intruders broke in, what data (if any) they stole, and when Christie's expected to have its main website back online.

Christie's did confirm its art mega-sale would continue as planned this Tuesday, but with bidding in person and by phone — not online. "We are looking forward to welcoming you to our exhibitions and to registering you to participate in these auctions," CEO Guillaume Cerruti said.

[3]

The latest security snafu comes less than a year after Christie's inadvertently [4]leaked location data belonging to hundreds of high-end art owners seeking to sell their paintings at auction.

[5]

[6]

That blunder, which came to light in August, was basically a privacy oversight by Christie's website, which allowed would-be customers to upload photos of the art they were seeking to sell.

As noticed by some clever clogs, some of these uploads included precise GPS coordinates revealing the exact location of some very pricey pieces. These physical addresses — which could guide would-be thieves to the buildings where the art resided — were publicly available to anyone online via the Christie's website, which had failed to strip out this location metadata from submitted snaps.

[7]

Christie's said it had since addressed that error. Another security slip-up, however, isn't a good look for the British auction house.

[8]Europol confirms incident following alleged auction of staff data

[9]Cybercriminals hit jackpot as 500k+ Ohio Lottery lovers lose out on their personal data

[10]CISA boss: Secure code is the 'only way to make ransomware a shocking anomaly'

[11]AI red-teaming tools helped X-Force break into a major tech manufacturer 'in 8 hours'

Meanwhile, cybercriminals continue their all-out assault on organizations across the globe, with recent break-ins and data-theft incidents hitting a wide range of targets from [12]Europol to the [13]Ohio Lottery .

These types of high-profile compromises were a hot topic of discussion among US officials and private-sector security firms alike at last week's [14]RSA Conference .

According to US Cybersecurity and Infrastructure Security Agency Director Jen Easterly, the only way to make cyberattacks, including ransomware infections, a " [15]shocking anomaly ," is by holding [16]technology makers — not end users — accountable for making their products more secure. ®

PS: UK newspaper publisher Newsquest, which is behind titles from the Oxford Mail and Southampton's Daily Echo to the Glasgow Times and Lancashire Telegraph, had its websites defaced by miscreants claiming to be Russian hackers over the weekend.

Get our [17]Tech Resources



[1] https://www.nytimes.com/2024/05/12/arts/design/christies-cyberattack.html

[2] https://dgc6x3fx379s3.cloudfront.net/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZkKNgaCnUe@-XY@VV8hafQAAAIc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.washingtonpost.com/technology/2023/08/21/christies-security-breach-location/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZkKNgaCnUe@-XY@VV8hafQAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZkKNgaCnUe@-XY@VV8hafQAAAIc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZkKNgaCnUe@-XY@VV8hafQAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/05/13/europol_data_breach/

[9] https://www.theregister.com/2024/05/10/cybercriminals_hit_jackpot_as_over/

[10] https://www.theregister.com/2024/05/08/cisa_ransomware_rsac/

[11] https://www.theregister.com/2024/05/13/ai_xforce_red_penetration/

[12] https://www.theregister.com/2024/05/13/europol_data_breach/

[13] https://www.theregister.com/2024/05/10/cybercriminals_hit_jackpot_as_over/

[14] https://www.theregister.com/special_features/spotlight_on_rsa/

[15] https://www.theregister.com/2024/05/08/cisa_ransomware_rsac/

[16] https://www.theregister.com/2024/05/09/68_tech_firms_sign_cisas/

[17] https://whitepapers.theregister.com/



Locked down

Snowy

According to US Cybersecurity and Infrastructure Security Agency Director Jen Easterly, the only way to make cyberattacks, including ransomware infections, a "shocking anomaly," is by holding technology makers — not end users — accountable for making their products more secure. ®

The only way that could work is if computers where more locked down that the iPhone. Intall only from the company store, run nothing they do not want you to or view any web site they do not deem to be safe.

Those at fault are culpable.

Tron

Sometimes that is the technology maker. More often it is the end user. In cases of hacks and malware it is the criminal. Victim blaming is tacky and unpleasant. Hold people responsible for what is their fault. Vicarious atonement to manipulate tech is not a solution.

If threatened by US government agencies, technology makers could withdraw their products from the US market until the threat is withdrawn. I'm sure America could function happily without tech for a bit.

"How should I know if it works? That's what beta testers are for. I only
coded it."
(Attributed to Linus Torvalds, somewhere in a posting)