LIVE · cybersecurity feed
Live wire
Employee benefits platform Paylogix says hackers stole financial and health dataAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning Repair
breach

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]

zeroday.news ·

The Los Angeles County Museum of Art (LACMA) has confirmed that a data breach last year exposed sensitive personal and medical information belonging to its customers and employees. The museum detected suspicious activity on its systems on July 11, 2025, which investigators later determined had begun four days prior.

A month after the initial detection, the museum's investigation confirmed that its network had been compromised. However, the specific types of data accessed by the attacker could not be immediately determined. The initial findings from the investigation became available in late February 2026, more than seven months after the breach was discovered.

Over a year after the incident began, LACMA identified that the compromised data may include full names, dates of birth, Social Security numbers, and driver's license or other government-issued identification numbers. Additionally, partial financial account numbers and partial payment card information were potentially exposed.

For some individuals, the breach also included health insurance information and medical details such as provider names, medical treatments, diagnoses, treatment dates, or treatment locations.

LACMA has reported the incident to law enforcement authorities and has begun sending personalized data breach notifications to affected individuals. These notifications advise recipients to monitor their bank accounts for unusual activity, consider placing a security freeze or fraud alert on their credit files, and report any attempts at identity theft to their financial institutions and law enforcement.

The museum is offering a one-year identity theft and fraud protection service through Financial Shield to impacted individuals, with an enrollment deadline of November 22. A dedicated phone line has also been established to provide support and answer questions for those affected by the breach.

LACMA, one of the largest art museums in the western United States, houses approximately 155,000 works of art spanning 6,000 years and typically attracts over a million visitors annually. The museum has not publicly disclosed the number of individuals impacted by the breach or the specific nature of the attack.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cyber

breach

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

phishing

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]

ai

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.

nation-state

58 arrested in international cybercrime crackdown

Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.

phishing

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]