LACMA data breach exposed Social Security numbers and medical records, museum confirms
The Los Angeles County Museum of Art says a July 2025 intrusion leaked names, SSNs, driver's licence numbers and health data. Notifications went out more than a year after detection.

Key points
- The Los Angeles County Museum of Art (LACMA) detected an intrusion on 11 July 2025 that had begun four days earlier, on 7 July.
- Investigators confirmed a network breach a month later, but only produced initial findings in late February 2026.
- Stolen data may include full names, dates of birth, Social Security numbers, driver's licence numbers, partial payment card data and medical information.
- LACMA has offered affected people one year of identity theft protection through Financial Shield, with an enrolment deadline of 22 November.
- The museum hasn't disclosed how many people are affected, or how the attackers got in.
LACMA, one of the largest art museums in the western United States, has told staff and customers that hackers broke into its network in July 2025 and made off with personal and medical information.
The museum spotted suspicious activity on 11 July 2025. The attackers had already been inside for four days. A follow-up investigation confirmed in August that the network was compromised, but LACMA couldn't determine at the time exactly what data had been taken.
That answer took another six months. First concrete results from the forensic review arrived in late February 2026, and personal notification letters have only now gone to affected individuals, well over a year after the original break-in. The gap is notable: we reported a similar lag after the Unlimited Technology Systems breach on 7 August, where hackers spent five days inside systems before anyone noticed.
What was stolen?
Much of it is the kind of data that enables identity theft for years. LACMA says the attacker may have accessed identity documents, partial financial details and medical records tied to individuals who had dealings with the museum.
| Data type | Detail |
|---|---|
| Identity | Full name, date of birth, Social Security number |
| Government ID | Driver's licence or other government-issued ID number |
| Financial | Partial bank account numbers, partial payment card numbers |
| Health | Health insurance information |
| Medical | Provider name, treatment, diagnosis, treatment dates and locations |
Medical records are unusual for an art museum. They suggest employee health plan data or benefits records sat on the same systems the attackers reached. LACMA hasn't said which population, visitors, members, donors or staff, each data category applies to.
Should ordinary people be worried?
If you've received a letter from LACMA, treat it seriously. Social Security numbers and driver's licence numbers don't change, and once leaked they can be used to open credit lines or file fraudulent tax returns years later.
LACMA is telling recipients to watch their bank statements for anything unfamiliar and to consider a security freeze or fraud alert on their credit file, a free process with the three US credit bureaus that blocks new accounts being opened in your name. Notification letters include an enrolment code for one year of identity theft protection through Financial Shield, deadline 22 November. A dedicated phone line has been set up for questions.
How did the attackers get in?
Unknown. LACMA hasn't described the intrusion method, whether ransomware (malicious software that locks files until a ransom is paid) was involved, or the total number of people affected. BleepingComputer put those questions to the museum and hadn't received a response by publication.
What's on the record: attackers inside on 7 July 2025, detection on 11 July, breach confirmed a month later, data analysis wrapped in February 2026, letters mailed in autumn 2026. That timeline is long by US standards and will likely draw scrutiny from state attorneys general in California and elsewhere.
LACMA houses around 155,000 works and has historically drawn more than a million visitors a year, so the pool of ticket buyers, donors and members whose data could sit in its systems is large. For anyone whose Social Security number now appears in a second breach notification this year, the calculus on whether a credit freeze is worth the hassle has probably shifted.



