Skip to main content

LACMA data breach last year exposed social security and medical data

0
High
Breach
Published: 08/25/2026 (08/25/2026, 21:58:14 UTC)
Source: Bleeping Computer

Description

The Los Angeles County Museum of Art (LACMA) experienced a data breach in July 2025 that exposed sensitive customer and employee information, including social security numbers, medical data, and partial financial details. The breach was detected four days after initial suspicious activity and confirmed a month later. Impacted individuals have been notified and offered identity theft protection services. Law enforcement has been informed, but details about the number of affected individuals and attack specifics remain undisclosed.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 12:24:46 UTC

Technical Analysis

In July 2025, LACMA detected unauthorized access to its network that began four days prior. An investigation revealed that attackers accessed sensitive personal information such as full names, dates of birth, social security numbers, government-issued IDs, partial financial account and payment card information, health insurance details, and medical treatment data. Notifications and support services were provided to affected individuals, including identity theft protection enrollment. The museum has involved law enforcement but has not publicly disclosed the attack vector or the total number of impacted individuals.

Potential Impact

The breach exposed highly sensitive personal data, including social security numbers and medical information, which could lead to identity theft, financial fraud, and privacy violations for affected individuals. The exposure of partial financial and payment card information further increases the risk of financial exploitation. The breach affects both customers and employees, potentially amplifying the scope of impact.

Defensive Guidance

LACMA has notified impacted individuals and law enforcement authorities. Affected persons are advised to monitor financial accounts, consider credit freezes or fraud alerts, and report any identity theft attempts. Enrollment in a one-year identity theft and fraud protection service is offered. No specific technical remediation or patch is applicable as this is a breach incident. Organizations should review and enhance their detection and response capabilities to identify suspicious activity promptly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/","fetched":true,"fetchedAt":"2026-08-25T22:37:15.125Z","wordCount":652}

Threat ID: 6a8e191bacd9273b49cbf29d

Added to database: 08/25/2026, 22:37:15 UTC

Last enriched: 09/10/2026, 12:24:46 UTC

Last updated: 10/02/2026, 14:26:20 UTC

Views: 73

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses