LACMA’s data breach last year exposed social and medical data

LACMA's data breach last year exposed social and medical data

The Los Angeles County Museum of Art (LACMA) announced that a breach last year exposed information about customers and employees.

The museum says that on July 11, 2025, it detected suspicious activity on its systems that began four days earlier. A month later, the investigation confirmed that the network had been compromised.

At the time, the nature of the disclosed data could not be determined, and the first results of the investigation became available at the end of February 2026.

image

More than a year after the discovery of the data leakage incident, the identified museum that the attacker may have gained access to the following information:

  • Full name
  • Date of birth
  • Social security number
  • Driver’s license or official identification number
  • Partial financial account numbers
  • Partial payment card information
  • Health Insurance Information
  • Medical information such as provider name, medical treatment, diagnosis, dates of treatment or locations of treatment

LACMA says it has notified law enforcement of the incident and sent personalized data breach notifications of the affected persons.

Recipients are advised to monitor their bank accounts for suspicious activity, consider placing a security freeze or fraud alert on their credit file, and report attempted identity theft to their financial institutions and law enforcement.

The letters include information on signing up for a year’s worth of identity theft and fraud protection through Financial Shield, with a November 22 deadline to sign up.

A dedicated telephone line has also been set up to provide support and answer questions for affected individuals.

LACMA is one of the largest art museums in the western United States, housing approximately 155,000 works spanning 6,000 years of art history. The museum has historically attracted over one million visitors annually.

BleepingComputer contacted LACMA with questions about the number of individuals affected, as well as the nature of the attack, but had not heard back by the time of publication.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *