LACMA Data Breach Exposed Social Security and Medical Information
Museum announces incident affecting customers and employees, details under investigation

Key Takeaways
- LACMA confirmed a data breach exposing Social Security numbers and medical data.
- The incident was publicly announced on August 25, 2026, though the breach occurred last year.
- The investigation into the cause, threat actor, and full scope is ongoing.
- No specific exploitation details, patch, or victim count have been provided in the available report.
Quick answers
- What happened?
- The Los Angeles County Museum of Art (LACMA) confirmed a data breach compromising personal information, including Social Security numbers and medical data, though specific technical details and the scope of affected individuals remain under investigation.
- What should defenders do?
- LACMA is implementing security improvements. Affected individuals are advised to monitor accounts and consider credit monitoring services.
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information, including Social Security numbers and medical data. The incident was made public on August 25, 2026. According to the report, the investigation into the cause and full extent of the exposure is ongoing. No specific threat actor, exploitation method, or patch has been identified in the available summary. The museum has not disclosed the number of affected individuals or the exact date of the original breach. LACMA stated it is implementing security improvements in response to the incident.
Security Details
Breach exposed Social Security numbers and medical data of customers and employees. Root cause, threat actor, and exploitation details are under investigation.
Mitigation
LACMA is implementing security improvements. Affected individuals are advised to monitor accounts and consider credit monitoring services.
Sources
BleepingComputer
LACMA data breach last year exposed social security and medical data
Aug 25, 2026 · 21:58
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



