Gagosian Listed by daixin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Gagosian was listed by the daixin ransomware group on September 11, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may be affected; those with any connection to the gallery should review any recent notices from Gagosian and consider changing passwords or enabling additional account protections.
On September 11, 2025, the global art gallery Gagosian was listed by the daixin ransomware group, which claims to have carried out a ransomware attack involving the exfiltration of internal files. Public detail remains limited: the number of people affected is unknown, and no further confirmation of the incident beyond the group's listing has been provided in available reports. For an organisation that handles sensitive commercial, client and operational information across multiple countries, any such claim raises clear questions about potential exposure of private data.
The listing itself is an unverified claim by the threat actor. What is known so far is confined to the reported fact of the listing and the description of internal files taken during a ransomware attack. No independent verification of the scale, method or precise contents has been made public.
Breaking down the breach
According to the available record, Gagosian was listed by the daixin ransomware group on September 11, 2025. The group asserts that internal files were exfiltrated as part of a ransomware attack. Beyond that statement, key details are undisclosed. The number of people affected is unknown. No public information has been released about the date the intrusion began, how access was obtained, which systems were involved, or whether any ransom demand was made or paid. The record does not describe the volume of data taken or confirm whether any files have been published. In short, the incident is known primarily through the group's own claim on its leak site; independent corroboration of the technical facts remains limited.
The group behind it: daixin
Daixin is a ransomware operation that has been active in recent years and is known for a double-extortion model. The group typically encrypts systems while also stealing data, then threatens to publish the stolen material on a dedicated leak site if payment is not received. Public reporting on daixin has documented its use of this approach against organisations in various sectors, with victim listings serving as both pressure and advertisement. The group claims responsibility for the Gagosian incident by placing the gallery on its leak site and stating that internal files were exfiltrated. No further statements attributed specifically to daixin about this victim—such as sample files, exact data volumes or negotiation details—appear in the public record provided. As with other listings by the group, the claim should be treated as an assertion by the threat actor rather than independently verified fact.
Who is Gagosian?
Gagosian is a major international art gallery established by Larry Gagosian in Los Angeles in 1980. It specialises in modern and contemporary art and operates eighteen exhibition spaces across the United States, Europe and Asia, employing more than three hundred people. Galleries of this scale routinely manage a wide range of sensitive information: client and collector contact details, transaction records, shipping and insurance documentation, employee data, and confidential correspondence about artworks and sales. Because the business spans multiple jurisdictions and deals with high-value assets and private individuals, a successful intrusion can affect both commercial confidentiality and personal privacy. The organisation's global footprint means any confirmed data exposure could have consequences for staff, clients and partners in several countries.
The information in question
The only data type named in the available facts is “internal files” said to have been exfiltrated in the ransomware attack. Exact contents are unconfirmed. Organisations of Gagosian's type typically hold employee records, client and collector personal information, financial and contractual documents, inventory and provenance data, and internal communications. Whether any of those categories were among the files taken has not been disclosed. Public reporting does not list specific file names, record counts or data categories beyond the general description of internal files. Readers should therefore treat any assumption about particular personal or commercial data as speculative until further verified information appears.
The real-world impact
If the claimed exfiltration is accurate, the primary risk to individuals is the possible exposure of personal or financial details that could be used for phishing, identity fraud or targeted social engineering. Staff whose employment records or contact information were stored internally could face unwanted contact or credential-stuffing attempts. Clients and collectors whose private details or transaction histories were held by the gallery could see that information misused. For the organisation itself, the consequences may include operational disruption, legal and regulatory obligations under data-protection laws in the jurisdictions where it operates, and reputational damage among artists, collectors and partners who expect confidentiality. Because the number of people affected and the precise data types remain unknown, the full scope of these risks cannot yet be quantified. The absence of confirmed publication of the files means the most immediate harm may still be latent rather than realised.
Were you affected?
If you have worked with, been employed by, or conducted business with Gagosian, treat the listing as a reason for caution rather than confirmed personal exposure. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and be alert to phishing messages that reference the gallery or art transactions. Change passwords on any accounts that may have reused credentials associated with Gagosian systems. Because the exact data taken is unconfirmed, there is no definitive public list of affected individuals. Readers can run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Stay informed through official statements from the organisation if and when they are issued, and avoid relying solely on claims made by the threat actor.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Communicare Inc. Listed by daixin Ransomware GroupInsurance Office of America Listed by daixin Ransomware GroupSGS Co Listed by daixin Ransomware GroupAcadian Ambulance Listed by daixin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Gagosian Listed by daixin Ransomware Group →
Publicly posted by daixin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.