TTO-2026-0827-003 · August 27, 2026 Data Breach

LACMA Data Breach Disclosed More Than a Year After Detection — SSNs, Medical Records, and Financial Data Exposed

lacma.orgDetected July 2025Disclosed August 2026SSNs driver licensesMedical diagnoses treatment datesPartial financial and payment card dataNumber of affected not disclosed13+ month gapNetwork compromise July 7-11 2025

Summary

The Los Angeles County Museum of Art disclosed in August 2026 that a network breach detected on July 11, 2025 exposed sensitive personal, financial, and medical information belonging to customers and employees. The breach began on July 7, 2025 and was contained by July 11. The investigation confirmed a network compromise in August 2025 but could not immediately determine what data had been accessed. A data review firm completed its analysis in late February 2026. LACMA has not disclosed the number of affected individuals and has not responded to media inquiries about the total scope of the breach. The data potentially exposed includes full names, dates of birth, Social Security numbers, driver's license and government-issued identification numbers, partial financial account numbers, partial payment card information, health insurance information, and medical details including provider names, diagnoses, treatment dates, and treatment locations. LACMA notified law enforcement and sent personalized breach notification letters to affected individuals. The disclosure comes more than thirteen months after the breach was initially detected and approximately six months after the full scope of exposed data was identified.

Timeline

DateEvent
Jul 7, 2025Unauthorized third party accesses LACMA network — breach begins
Jul 11, 2025LACMA detects suspicious activity — breach contained
Aug 2025Investigation confirms network compromise — data type unknown at this stage
Late Feb 2026Data review firm completes analysis — full scope of exposed data identified
Aug 2026LACMA sends personalized breach notifications to affected individuals
Aug 26, 2026Public disclosure — more than 13 months after initial detection — affected individual count not disclosed

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
lacma.org86.0Live
WarmBadge Intelligence Snapshot · Captured: August 27, 2026 UTC

Context

lacma.org scores 86.0 — a strong score reflecting an established cultural institution with solid infrastructure and a positive reputation profile built across decades of public-facing operations. A high domain trust score does not predict breach risk. It reflects the accumulated state of the domain's trust signals — infrastructure, network graph position, reputation — at the moment of evaluation. An organization can maintain excellent trust infrastructure while simultaneously carrying a network breach in its environment for more than a year before public disclosure. The gap between detection and disclosure in the LACMA case — thirteen months — is not exceptional by 2026 healthcare and cultural institution standards, which makes it no less significant for affected individuals. Social Security numbers, medical diagnoses, and treatment information were potentially accessible to an unauthorized party for a period whose boundaries are known only to LACMA and its investigators. The affected individuals learned about this in August 2026.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · August 27, 2026