Skip to content

ArtNexus Database Allegedly Left Public, Exposing 3,314 Collectors and Galleries With Addresses and Payment Tokens

Breach Report Colombia flagColombia Art Market / Marketplace Reported Live

ArtNexus Database Allegedly Left Public, Exposing 3,314 Collectors and Galleries With Addresses and Payment Tokens

An actor posting as exfilar claims that ArtNexus, a Colombian fine art magazine and marketplace connecting galleries, collectors, and curators across 37 countries, left its backend database publicly readable with no authentication. The dump is said to contain 3,314 unique email addresses belonging to gallery owners, private collectors, museum curators, and dealers, 3,455 user accounts, 834 physical addresses with phone numbers, 389 art purchase transactions with items and amounts, and 512 payment source tokens in plaintext. Also included are private buyer-seller negotiation messages. Access is reported as still live. The claim is unverified.

StatusReported live
Individuals3,314
Payment tokens512
Actorexfilar

Post details

TargetArtNexus
CountryColombia flagColombia
SectorArt market / Publishing
ListingReply or upgrade to unlock
Volume18MB raw export
Reach37 countries, 339 cities
Observed
Actorexfilar

!Allegedly included

  • Collector email addresses
  • Gallery owner contacts
  • Curator & dealer emails
  • User account identifiers
  • Shipping addresses
  • Phone numbers
  • Purchase transactions
  • Artwork names & amounts
  • Checkout records
  • Payment source tokens
  • Negotiation messages
  • Gallery following lists
  • Subscription records
  • Backend infrastructure details

Screenshots

Potential impact

The population is small but unusually exposed. This dataset links named collectors to the artworks they bought, what they paid, and the address it shipped to, which is inventory information for high-value portable goods sitting in identified private homes across 37 countries. Discretion is a working condition in this market, and the negotiation messages expose commercial terms parties expected to stay private. On the payment tokens, the actor is explicit that the corresponding secret key is not in the dump, so the tokens are not directly chargeable as published; the claim is that a further key disclosure would change that. Backend infrastructure details are reported as reachable now.

iStatus

Unverified

Dark Web Informer is not reproducing the database location, backend host, image server address, or any payment tokens, all of which appear in the post while the exposure is reported as unremediated. This is the twelfth of a stated 25 releases from the same automated scanning operation behind two disclosures published days earlier, with the actor claiming cumulative totals in the hundreds of databases. The post also advertises the actor's paid penetration testing services, which sits awkwardly alongside publishing victim data. The claim is unverified.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest