Back to Feed
BreachesAug 25, 2026

LACMA data breach last year exposed social security and medical data

LACMA data breach exposed social security, medical, and financial information.

Summary

The Los Angeles County Museum of Art (LACMA) has disclosed a data breach that occurred last year, exposing sensitive customer and employee information. The breach, detected in July 2025, compromised network systems and potentially accessed full names, social security numbers, driver's license details, partial financial and payment card information, and extensive medical data. LACMA is notifying affected individuals and offering identity theft protection services.

Full text

LACMA data breach last year exposed social security and medical data By Bill Toulas August 25, 2026 05:58 PM 0 The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. The museum says that on July 11, 2025, it detected suspicious activity on its systems that had started four days earlier. A month later, the investigation confirmed that the network was compromised. At the time, the type of exposed data could not be determined, and the first results of the investigation became available in late February 2026. More than a year after the discovery of the data breach incident, the museum identified that the following information may have been accessed by the attacker: Full name Date of birth Social Security number Driver’s license or government-issued identification number Partial financial account numbers Partial payment card information Health insurance information Medical information such as provider name, medical treatment, diagnosis, treatment dates, or treatment locations LACMA says it has notified law enforcement authorities about the incident and sent personalized data breach notifications to impacted individuals. Recipients are recommended to monitor their bank accounts for suspicious activity, consider placing a security freeze or fraud alert on their credit file, and report identity theft attempts to their financial institutions and law enforcement. The letters include information on enrolling in a one-year identity theft and fraud protection service through Financial Shield, with an enrollment deadline of November 22. A dedicated phone line has also been set up to provide support and answer questions for impacted individuals. LACMA is one of the largest art museums in the western United States, housing around 155,000 works spanning 6,000 years of art history. The museum has historically attracted over one million visitors annually. BleepingComputer has contacted LACMA with questions about the number of impacted individuals, as well as the nature of the attack, but we have not heard back as of publication. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: OnTrac notifies customers of data breach after network hackErnst & Young discloses data breach after support system hackSakura Internet hack exposes data of up to 1.36 million accountsHealthtech firm CareCloud data breach impacts 3.7 million patientsSafePal data breach impacts 39,798 customers, stolen info for sale

Entities

Financial Shield (product)