LACMA data breach last year exposed social security and medical data
The Los Angeles County Museum of Art (LACMA) has announced a data breach last year that exposed customer and employee information, including social security numbers, medical data, and financial information.
Intelligence analysis by Llama

A data breach at the Los Angeles County Museum of Art (LACMA) exposed sensitive information, including social security numbers and medical data. The museum has notified law enforcement and impacted individuals, and is offering identity theft protection services.
Imagine someone broke into the Los Angeles County Museum of Art's computer system and stole information about visitors and employees, including their social security numbers and medical data. This is a serious security incident that could have serious consequences for the people affected.
Analysis
Background
The Los Angeles County Museum of Art (LACMA) is one of the largest art museums in the western United States, housing around 155,000 works spanning 6,000 years of art history. The museum has historically attracted over one million visitors annually.
What Happened
On July 11, 2025, LACMA detected suspicious activity on its systems that had started four days earlier. A month later, the investigation confirmed that the network was compromised. At the time, the type of exposed data could not be determined, and the first results of the investigation became available in late February 2026.
What Was Exposed
LACMA says that the following information may have been accessed by the attacker:
- Full name
- Date of birth
- Social Security number
- Driver’s license or government-issued identification number
- Partial financial account numbers
- Partial payment card information
- Health insurance information
- Medical information such as provider name, medical treatment, diagnosis, treatment dates, or treatment locations
Response
LACMA has notified law enforcement authorities about the incident and sent personalized data breach notifications to impacted individuals. Recipients are recommended to monitor their bank accounts for suspicious activity, consider placing a security freeze or fraud alert on their credit file, and report identity theft attempts to their financial institutions and law enforcement. The letters include information on enrolling in a one-year identity theft and fraud protection service through Financial Shield, with an enrollment deadline of November 22. A dedicated phone line has also been set up to provide support and answer questions for impacted individuals.
Key points
- LACMA detected suspicious activity on its systems on July 11, 2025, and confirmed a network compromise a month later.
- The investigation revealed that the following information may have been accessed by the attacker: full name, date of birth, social security number, driver’s license or government-issued identification number, partial financial account numbers, partial payment card information,…
- LACMA has notified law enforcement authorities and sent personalized data breach notifications to impacted individuals.
- Recipients are recommended to monitor their bank accounts for suspicious activity, consider placing a security freeze or fraud alert on their credit file, and report identity theft attempts to their financial institutions and law enforcement.
LACMA's response to the data breach, including notifying law enforcement and impacted individuals, and offering identity theft protection services, demonstrates a commitment to protecting sensitive information and supporting those affected by the incident.
The data breach at LACMA highlights the potential consequences of a security incident, including identity theft and financial loss. Impacted individuals should be vigilant in monitoring their financial accounts and credit reports for suspicious activity.



