LACMA data breach exposed Social Security numbers and medical records, museum confirms
The Los Angeles County Museum of Art says a July 2025 intrusion leaked names, SSNs, driver's licence numbers and health data. Notifications went out more than a year after detection.

Key points
- The Los Angeles County Museum of Art (LACMA) detected an intrusion on 11 July 2025 that had begun four days earlier, on 7 July.
- Investigators confirmed a network breach a month later, but only produced initial findings in late February 2026.
- Stolen data may include full names, dates of birth, Social Security numbers, driver's licence numbers, partial payment card data and medical information.
- LACMA has offered affected people one year of identity theft protection through Financial Shield, with an enrolment deadline of 22 November.
- The museum has not disclosed how many people are affected, or how the attackers got in.
LACMA, one of the largest art museums in the western United States, has told customers and employees that hackers broke into its computer network in July 2025 and stole a wide range of personal and medical information.
The museum spotted the intrusion on 11 July 2025. By then the attackers had already been inside for four days. A follow-up investigation confirmed in August that the network had been breached, but LACMA says it could not work out at the time exactly what data had been taken.
That answer took another six months. The first concrete results of the forensic review only landed in late February 2026, and personal notification letters have gone out to affected individuals now, well over a year after the original break-in.
What was stolen?
A lot, and much of it is the sort of data that fuels identity theft for years. LACMA says the attacker may have accessed a mix of identity documents, partial financial details and medical records tied to individuals who had dealings with the museum.
The categories LACMA has listed include:
| Data type | Detail |
|---|---|
| Identity | Full name, date of birth, Social Security number |
| Government ID | Driver's licence or other government-issued ID number |
| Financial | Partial bank account numbers, partial payment card numbers |
| Health | Health insurance information |
| Medical | Provider name, treatment, diagnosis, treatment dates and locations |
The presence of medical records is unusual for an art museum and suggests employee health plan data, or benefits records, sat on the same systems the attackers reached. LACMA has not spelled out which population (visitors, members, donors, staff) each data category applies to.
Should ordinary people be worried?
If you get a letter from LACMA, yes, treat it seriously. Social Security numbers and driver's licence numbers do not change, and once leaked they can be used to open credit lines or file fraudulent tax returns for a long time afterwards.
LACMA is telling recipients to watch their bank and card statements for anything unfamiliar, and to consider a security freeze or fraud alert on their credit file (a free process with the three US credit bureaus that stops new accounts being opened in your name). The letters also include an enrolment code for one year of identity theft and fraud protection through a provider called Financial Shield, with a deadline of 22 November.
A dedicated phone line has been set up for questions.
How did the attackers get in?
Unclear. LACMA has not described the intrusion method, whether ransomware, meaning malicious software that locks files until a payment is made, was involved, or how many people are affected in total. BleepingComputer asked the museum those questions and had not received a response at publication.
What is on the record is the timeline: attackers inside on 7 July 2025, detection on 11 July, breach confirmed a month later, data analysis wrapped up in February 2026, letters mailed in autumn 2026. That gap between detection and notification is long by US standards, and is likely to draw attention from state attorneys general in California and elsewhere.
LACMA houses around 155,000 works and has historically drawn more than a million visitors a year, so the pool of members, donors and ticket buyers whose data could sit in its systems is large.



