GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

LACMA Discloses Data Breach Exposing SSNs and Medical Records

The Los Angeles County Museum of Art says a 2023 security incident compromised sensitive personal data belonging to staff and visitors.

The Los Angeles County Museum of Art has revealed that a breach discovered last year resulted in the exposure of sensitive personal information belonging to both employees and members of the public. According to the museum's notification, the compromised data includes Social Security numbers and medical information, putting affected individuals at heightened risk of identity theft and fraud.

Details on how the attackers gained access and how many people were affected remain limited. As is typical with these delayed disclosures, LACMA is offering credit monitoring services to those impacted and has notified relevant authorities.

The museum joins a growing list of cultural and nonprofit institutions targeted by cybercriminals who increasingly see under-resourced organizations as easy marks for data theft.

Why it matters: Museums, nonprofits, and other organizations outside the traditional tech and finance sectors often hold troves of sensitive employee and donor data while investing far less in security infrastructure. This breach is a reminder that any organization handling SSNs or health data is a viable ransomware or data-theft target, regardless of its core mission.

Sources: BleepingComputer