The Los Angeles County Museum of Art (LACMA) disclosed that a network compromise may have exposed sensitive information belonging to visitors, customers, and employees, including Social Security numbers, personal and financial data, health-insurance information, and medical records. LACMA detected suspicious activity on July 11, 2025, found that the activity had begun four days earlier, and confirmed a network compromise about a month later; by late February 2026, its investigation determined the attacker may have accessed the sensitive data.
LACMA notified law enforcement and affected individuals, though it did not disclose the attack method or number of people affected. The museum is offering one year of Financial Shield identity-theft and fraud-protection services and advises recipients to monitor their accounts and consider credit freezes or fraud alerts.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Initial investigation results indicated that an attacker may have accessed names, dates of birth, Social Security and identification numbers, partial financial and payment-card data, health-insurance data, and medical information.
About one month after detecting the suspicious activity, LACMA confirmed that its network had been compromised. The museum initially could not determine the types of data exposed.
The Los Angeles County Museum of Art detected suspicious activity in its systems and began investigating the incident.
LACMA said the suspicious activity associated with the incident began four days before it was detected.
LACMA notified law enforcement and sent individualized breach notifications to affected people, offering one year of Financial Shield identity-theft and fraud-protection services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemkd-cirt.mk
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.