Ransomware victim disclosure
← All victimsGagosian
Claimed by Daixin · listed 8 months ago
Status timeline
- Listed
Sep 11, 2025
- Data leaked
At a glance
- Group
- Daixin
- Status
- Data leaked
- Country
- United States
- Sector
- Not Found
- Listed on leak site
- Sep 11, 2025
About the victim
AI dossier — public-source company profileGagosian is a leading global contemporary and modern art gallery founded by Larry Gagosian in Los Angeles in 1980. It operates eighteen exhibition spaces across the United States, Europe, and Asia, employing more than three hundred people. The gallery represents and exhibits major international artists, hosts exhibitions, publishes the Gagosian Quarterly, and operates an online shop.
- Industry
- Contemporary & Modern Art Galleries
- Address
- 456 North Camden Drive, Beverly Hills, CA (flagship US location; global HQ not formally stated)
- Employees
- 300+
- Founded
- 1980
Attack summary
Severity: high — Data has been published (not merely listed), indicating confirmed exfiltration. Gagosian handles high-net-worth client PII, significant financial transactions, and proprietary business data across 18 global locations, representing meaningful exposure of sensitive business and personal information at scale.The Daixin ransomware group claims to have compromised Gagosian and has published data (disclosed status: data_published), asserting access to internal company data. The specific nature of exfiltrated data (e.g., employee records, client/collector PII, financial data) is not detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Internal company data
- Potentially employee records (300+ staff)
- Potentially client/collector information
- Potentially financial or transactional records
What the group claims
Established by Larry Gagosian in Los Angeles in 1980, Gagosian is a global gallery specializing in modern and contemporary art that employs more than three hundred people at eighteen exhibition spaces across the United States, Europe, and Asia.
Sources
- Victim sitegagosian.com
Source
Indexed 8 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
