LACMA data breach last year exposed social security and medical data
Description
The Los Angeles County Museum of Art (LACMA) experienced a data breach in July 2025 that exposed sensitive customer and employee information, including social security numbers, medical data, and partial financial details. The breach was detected four days after initial suspicious activity and confirmed a month later. Impacted individuals have been notified and offered identity theft protection services. Law enforcement has been informed, but details about the number of affected individuals and attack specifics remain undisclosed.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In July 2025, LACMA detected unauthorized access to its network that began four days prior. An investigation revealed that attackers accessed sensitive personal information such as full names, dates of birth, social security numbers, government-issued IDs, partial financial account and payment card information, health insurance details, and medical treatment data. Notifications and support services were provided to affected individuals, including identity theft protection enrollment. The museum has involved law enforcement but has not publicly disclosed the attack vector or the total number of impacted individuals.
Potential Impact
The breach exposed highly sensitive personal data, including social security numbers and medical information, which could lead to identity theft, financial fraud, and privacy violations for affected individuals. The exposure of partial financial and payment card information further increases the risk of financial exploitation. The breach affects both customers and employees, potentially amplifying the scope of impact.
Defensive Guidance
LACMA has notified impacted individuals and law enforcement authorities. Affected persons are advised to monitor financial accounts, consider credit freezes or fraud alerts, and report any identity theft attempts. Enrollment in a one-year identity theft and fraud protection service is offered. No specific technical remediation or patch is applicable as this is a breach incident. Organizations should review and enhance their detection and response capabilities to identify suspicious activity promptly.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/","fetched":true,"fetchedAt":"2026-08-25T22:37:15.125Z","wordCount":652}
Threat ID: 6a8e191bacd9273b49cbf29d
Added to database: 08/25/2026, 22:37:15 UTC
Last enriched: 09/10/2026, 12:24:46 UTC
Last updated: 10/02/2026, 14:26:20 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.