
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information.
The museum says that on July 11, 2025, it detected suspicious activity on its systems that had started four days earlier. A month later, the investigation confirmed that the network was compromised.
At the time, the type of exposed data could not be determined, and the first results of the investigation became available in late February 2026.
More than a year after the discovery of the data breach incident, the museum identified that the following information may have been accessed by the attacker:
- Full name
- Date of birth
- Social Security number
- Driver’s license or government-issued identification number
- Partial financial account numbers
- Partial payment card information
- Health insurance information
- Medical information such as provider name, medical treatment, diagnosis, treatment dates, or treatment locations
LACMA says it has notified law enforcement authorities about the incident and sent personalized data breach notifications to impacted individuals.
