Post

LACMA Data Breach Exposed Sensitive Information

LACMA Data Breach Exposed Sensitive Information

LACMA Data Breach Exposed Sensitive Information

The Los Angeles County Museum of Art (LACMA) has announced that a data breach last year exposed customer and employee information. 🚨 The museum reported that on July 11, 2025, it detected suspicious activity on its systems, which had initially started four days earlier. A month later, the investigation definitively confirmed that the network was compromised.

Crucially, at the time, the specific type of exposed data could not be determined, and the first results of this in-depth investigation became available in late February 2026.

Ultimately, more than a year after the discovery of the data breach incident, LACMA identified that the following sensitive information may have been accessed by the attacker:

  • Full name
  • Date of birth
  • Social Security number
  • Driver’s license or government-issued identification number
  • Partial financial account numbers
  • Partial payment card information
  • Health insurance information
  • Medical information such as provider name, medical treatment, diagnosis, treatment dates, or treatment locations.

In response to the incident, LACMA says it has notified law enforcement authorities and sent personalized data breach notifications to impacted individuals. To safeguard against potential harm, recipients are strongly recommended to monitor their bank accounts for suspicious activity, consider placing a security freeze or fraud alert on their credit file, and report any identity theft attempts to their financial institutions and law enforcement. Furthermore, the notification letters include information on enrolling in a one-year identity theft and fraud protection service through Financial Shield, with an enrollment deadline of November 22.

Read full article

This post is licensed under CC BY 4.0 by the author.