← SecureAZ Blog

Incident Response · 6 min read · Published 25 August 2026

Sotheby's NZ Breach: Why a Supplier's Data Leak Becomes Your Phishing Problem

Sotheby's International confirmed a breach of a third-party marketing platform holding client names, emails and phone numbers. The breach itself is contained. The phishing wave that follows is the part NZ businesses need to prepare for.

On 25 August 2026, RNZ reported that Sotheby's International, the luxury real estate brand, had confirmed unauthorised access to a third-party software platform it uses to store marketing contact information. The data involved is names, addresses, email addresses and phone numbers. The attacker claimed access to 1.6 million contacts. Sotheby's disputed that figure, saying many entries were duplicates.

New Zealand managing director Mark Harris confirmed the company had engaged independent cyber security specialists, and that email exchanges, property documentation and the systems used for financial transactions were not affected. Anyone whose open-text notes fields contained sensitive information will be contacted directly.

On the surface this is a contained incident with a fast, transparent response. That part deserves credit. But for every other NZ business, the important lesson is not what happened at Sotheby's. It is what happens next, and it will happen to the people on that list, not to Sotheby's.

The breach is the shopping list, not the attack

Names, emails and phone numbers do not sound dramatic next to passwords or credit card numbers. Attackers disagree. A verified contact list tied to a specific brand relationship is the raw material for targeted phishing, and it is worth far more than the same names scraped at random.

Consider what an attacker holding this data actually knows about each person:

  • They have a real relationship with a luxury real estate firm
  • They are likely to be buying or selling high-value property, or have recently done so
  • Their email address and mobile number are confirmed as current
  • They may have notes attached describing their situation, timing or preferences

That is enough to write an email that looks completely legitimate. "Following our recent security incident, please verify your account." "Your settlement details have been updated, please confirm the new account number." "Your agent has shared a document with you." Each of these arrives from a sender that appears to be Sotheby's, references a real relationship, and lands at the exact moment the recipient has heard on the news that Sotheby's was breached and is expecting contact.

This pattern is well established. We covered the same dynamic after the ManageMyHealth breach, where the follow-on phishing campaigns impersonating the breached provider caused more direct harm to individuals than the original data exposure. The breach makes the news. The phishing does the damage.

Why third-party platforms are the soft target

Sotheby's did not have its own systems compromised. A marketing platform it relies on did. This is now the dominant pattern in NZ business breaches, and it is worth being clear about why.

Every business runs on a stack of external tools: CRM, email marketing, booking systems, document signing, accounting, support desks. Each of them holds a copy of your customer data. Each of them has its own security posture, its own staff, its own vulnerabilities. Your customer list is only as safe as the weakest platform it lives in.

Attackers know this. Compromising one marketing platform yields the contact lists of hundreds of client companies in one go. It is a far better return than attacking those companies individually. The NCSC supply chain security guidance exists because this is no longer an edge case. We wrote about the mechanics in how supply chain attacks reach your business through your vendors.

What the Privacy Act requires when it happens to you

Under the Privacy Act 2020, a business that suffers a privacy breach likely to cause serious harm must notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable. The obligation sits with the organisation that holds the relationship with the individual, even when the breach occurred at a supplier.

That means if your email marketing provider is compromised, you are the one filing the notification and contacting your customers. Contracts with suppliers should say so explicitly: who notifies whom, within what timeframe, and who bears the cost. Most NZ SMEs have never read the security clauses in their SaaS agreements. This is a good week to start. Our guide to Privacy Act 2020 obligations and staff training covers what the Act expects of your people.

What to do this week

1. Inventory where your customer data lives. List every external platform that holds names, emails or phone numbers for your customers. Most businesses find the number is between eight and twenty. You cannot protect data you do not know you have shared.

2. Turn on multi-factor authentication on every one of them. Marketing platforms, CRMs and support tools are routinely compromised through a single reused password. MFA on the admin accounts closes the most common door. See our MFA guide for small business.

3. Brief your staff on impersonation phishing. After any publicised breach, expect emails and texts impersonating the breached company, and also impersonating your own company to your customers. Staff should treat any message about "updated bank details" or "verify your account" as hostile until confirmed by phone on a known number. The warning signs of phishing attacks apply doubly when the sender is a brand in the news.

4. Fix the payment redirect gap. The highest-value attack against real estate, legal and professional services clients is settlement account fraud: a convincing email changes the bank account for a large payment. Every business handling client funds needs a rule that account changes are verified by phone, every time, no exceptions. This is the core of business email compromise, and it is where a leaked contact list turns into a six-figure loss.

5. Know your notification plan before you need it. Who calls the Privacy Commissioner, who drafts the customer email, who talks to the media. Sotheby's response was fast because those decisions had clearly been made in advance.

The training angle

Nothing in this incident required a sophisticated attack on Sotheby's. The next stage will not require one either. It will be an email, sent to a person, that looks right. Whether it works depends entirely on whether that person pauses.

That is the layer NZ businesses consistently under-invest in. Firewalls and endpoint tools do not stop a well-written email from a "trusted" sender. A trained team does. If your staff have never seen a realistic phishing simulation built on exactly this scenario, they will meet it for the first time when it is real.

SecureAZ runs security awareness training and phishing simulations built around the attacks NZ businesses actually face, including supplier-impersonation and payment-redirect scenarios. It is free for up to five users, and takes minutes to set up. Start your free trial and run the Sotheby's scenario against your own team this week.

Sources & references