The Los Angeles County Museum of Art has disclosed that a cyberattack exposed sensitive customer and employee information, including Social Security numbers and medical data.
LACMA detected suspicious activity on July 11, 2025. The museum says the activity began four days earlier, and investigators confirmed that attackers had compromised its network in August 2025.
The museum completed its review of the affected data in early 2026.
Breach may have exposed sensitive personal details
The LACMA data breach may have exposed full names, dates of birth, Social Security numbers and driver’s licence or other government-issued identification numbers.
Attackers may also have accessed partial financial account and payment-card information.
In addition, the museum says the exposed data may include health insurance information and medical details. Those records could include a healthcare provider’s name, diagnoses, treatments, treatment dates and treatment locations.
Museum sends breach notifications
LACMA has notified law enforcement and sent individual notices to people affected by the incident.
The museum has also offered one year of identity theft and fraud protection through Financial Shield. Eligible recipients must enrol by November 22.
LACMA created a dedicated phone line to answer questions and provide support to affected individuals.
LACMA has not disclosed the breach scope
The museum has not said how many people the LACMA data breach affected. It has also not identified the attackers or explained how they accessed the network.
People who received a notification should monitor bank accounts and credit reports for suspicious activity. They may also consider placing a fraud alert or security freeze on their credit file.
LACMA holds around 155,000 works of art and has historically attracted more than one million visitors each year.


0 responses to “LACMA Data Breach Exposed Social Security and Medical Data”