Shopping & subscriptions

LACMA account hacked? Here’s what to do

Move fast and in the right order: reclaim the account through LACMA’s official flow, kick the attacker out of every session, then close the door they came through — usually a password that leaked in a breach and was reused.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn

The LACMA letter arriving now is about a break-in that happened in July 2025

If a letter from the Los Angeles County Museum of Art turned up in your post, the incident behind it is more than a year old. LACMA's own notice, dated 24 August 2026, says an unauthorised third party was inside part of its network from 7 to 11 July 2025, that the museum spotted the activity on 11 July, and that the review of which files were touched only produced results in late February 2026. What the notice lists as potentially involved is unusually broad for a museum: full name, date of birth, Social Security number, driver's licence or other government-issued ID number, limited financial account numbers, limited payment card information, health-insurance information, and limited medical information such as provider name, diagnosis, treatment and treatment locations. None of that is a password problem, so there is nothing here to reset in a hurry. It is an identity problem, and the moves that count are a credit freeze and a careful reading of your own letter.

LACMA's own notice

LACMA, "Notice of Data Security Incident", 24 August 2026. Reported by BleepingComputer on 25 August 2026, with follow-ups in SC Media, ARTnews and Artforum.

Quick answer

If your LACMA account was hacked: start recovery at the official page (www.lacma.org/notice-data-security-incident), change the password to a unique one, sign out all other sessions, and re-check the recovery email and phone on the account. Then find out how the attacker got in — check whether your password appears in known breach data — and turn on two-factor authentication so it can’t happen again.

Recover your LACMA account, step by step

These steps follow LACMA’s official process. Official links only: account recovery · password reset.

1

Read your letter properly and note which categories it lists for you, since that determines everything that follows. A letter naming a Social Security number is a different situation from one naming an email address, and only the letter distinguishes them.

2

Freeze your credit file at Equifax, Experian and TransUnion. It is free, it takes about ten minutes per bureau online, and you can lift it temporarily when you actually need credit. This is the single most useful step for anyone whose Social Security number appeared in the notice.

3

If your letter came with an enrolment code, use it before the deadline. Press coverage put the offer at one year of identity-theft protection through Financial Shield with enrolment closing on 22 November, and the code only works from the letter itself.

4

If nothing has arrived and you think you should be on the list, call the dedicated line on (844) 953-2547 rather than the museum's general enquiries number, and ask whether your record is among the notified.

5

If health-insurance or medical information was listed for you, request a claims history from your insurer and read the next few explanation-of-benefits statements line by line, looking for providers, dates or treatments that are not yours.

6

If you hold a MyLACMA account, change its password to something unique and change it anywhere you reused it, then report any actual misuse at IdentityTheft.gov, which produces the recovery plan and the affidavit that banks and insurers ask for.

What trips people up with LACMA

  • Check which LACMA you have landed on, because the abbreviation is shared and the search results mix them up. This incident is the Los Angeles County Museum of Art on Wilshire Boulevard, not the Los Angeles County Medical Association. The presence of diagnoses and health-insurance details in the museum's notice makes the confusion worse, not better, so read the letterhead on anything you receive before acting on it.
  • A Social Security number and a date of birth do not expire and cannot be reset, which is why the standard advice to change your password is beside the point here. The action that actually blocks the common harm is a security freeze at all three credit bureaus, it is free by law, and it stops new accounts being opened in your name whether or not you were in the affected files.
  • Your own letter is the only document that tells you which categories applied to you, because LACMA states explicitly that the data types varied across individuals. The website notice lists everything that was present somewhere in the affected files, so reading it as a description of your own exposure will either frighten you unnecessarily or leave you under-reacting. If no letter arrived and you want to know where you stand, the museum set up a call centre on (844) 953-2547.
  • The health-insurance and medical fields open a door that a credit freeze does not close. Medical identity theft shows up as treatment you never received appearing on an explanation of benefits, or a deductible that is mysteriously used up, and it is usually caught by reading those statements rather than by watching a credit report. Ask your insurer for a record of claims paid in your name and query anything you do not recognise.
  • Notices this well covered breed convincing fakes within days. A genuine LACMA letter does not ask for your Social Security number back, does not want a payment to activate protection, and does not send you to a shortened link. If a message wants any of that, ignore it and go to lacma.org yourself or ring the number on the printed letter, not the one in the email.

What happened at LACMA, and why a museum was holding medical data

The dates come from LACMA's own notice and they are worth having straight. Suspicious activity on the museum's systems was detected on 11 July 2025. By August 2025 the investigation had established that someone had been inside a portion of the network from 7 to 11 July, four days in total. Identifying which files had actually been touched took much longer: LACMA engaged a data-review firm, received the initial results in late February 2026, and then spent further months, by its own account, working out current contact details for the people involved. The public notice went up on 24 August 2026, thirteen months after the intrusion, and personalised letters went out around the same time.

The list of data types is the part that surprises people, and the museum's phrasing matters: these are the categories that may have been present across the affected files, and it says plainly that the categories varied from person to person. Full name and date of birth, Social Security number, driver's licence or other government-issued identification number, limited financial account numbers, limited payment card information, health-insurance information, and limited medical information down to provider name, diagnosis, treatment dates and treatment locations. A museum does not collect diagnoses from ticket buyers. Fields like these normally sit in employment and benefits records, which fits the reporting from SC Media that both customer and employee information was caught, and it is why the museum's own staff have the most exposure here rather than someone who bought a timed-entry ticket.

LACMA has not published how many people were notified, and BleepingComputer said it asked and had no answer by publication. The gap between the February data-review results and the August letters is what the legal follow-up is built on: ARTnews and Artforum reported in late August 2026 that a former employee filed a proposed class action in California Superior Court alleging the museum was negligent and took far too long to tell anyone. The public notice on lacma.org points people to fraud alerts, security freezes and IdentityTheft.gov rather than offering a monitoring product, while BleepingComputer reported that the mailed letters carry a year of identity-theft protection through Financial Shield with a 22 November enrolment deadline. That difference is a good reason to keep the letter rather than the web page.

Still logged in? Lock the account down now

If you can still get in, you're racing the attacker. In this order: change the password to a long, unique one; sign out all other sessions/devices (the setting exists in LACMA's security settings); confirm the recovery email and phone number are yours (attackers quietly add their own so they can "recover" the account later); remove unfamiliar linked apps or API access; and turn on two-factor authentication. Only then deal with anything the attacker posted, sent or bought.

Locked out of LACMA — email or phone was changed

This is the worst-case scenario and the most common complaint: the attacker changed the account email, phone number or password so the normal reset flow emails them, not you. Do NOT keep triggering password resets — they go to the hacker. Go straight to LACMA's dedicated recovery flow (link above), which is built for exactly this case: it verifies you by your original signup details, previous passwords, linked devices or a government ID / selfie check, bypassing the stolen email. Watch for the security notice LACMA sent to your OLD email when the address was changed — it usually contains a "revert this change" link that works for a limited time and is the fastest way back in.

Got a "new login" alert from LACMA?

Treat it as real but verify it the safe way: never tap the link in the message itself (fake login alerts are a top phishing template for LACMA). Open the app or type the address yourself, check the active-sessions list in security settings, and if you see a device or location you don't recognize, sign it out and change your password immediately. If the alert was genuine, that password is burned — assume it's circulating and change it everywhere else you reused it.

Why this happened — and how to make sure it can’t again

About a third of account takeovers are credential stuffing: a password you used on LACMA (or the email behind it) leaked in some other company’s breach, and attackers replayed it here automatically. The FBI’s IC3 logged over 5,100 account-takeover complaints with $262M in losses in 2025 alone (IC3). Even when LACMA itself was never breached, your reused password from another site opens it.

So after recovery, check what’s already out there: our free scanner shows which known breaches and dark-web dumps include your email — and whether passwords were exposed with it.

Check my exposure — free →

After you recover: three doors to close

  1. Unique password + 2FA. A password manager plus app-based two-factor stops both stuffing and phishing replays.
  2. Reset everywhere you reused that password — email first (it’s the master key), then bank, then the rest.
  3. Shrink your public footprint. Attackers research targets on data-broker sites (your address, phone, relatives — enough to social-engineer support lines). Our free opt-out guide covers 190 of them, step by step.
Common questions

Hacked LACMA account, answered

How did my LACMA account get hacked?

The most common cause isn't a hack of LACMA itself — it's credential stuffing: a password you used on LACMA leaked from some other site's breach, and attackers tried it here automatically. Roughly a third of account takeovers happen this way, with phishing (fake LACMA login pages and alerts) close behind. That's why the first fix is a unique password, not just a new one.

Can I get my LACMA account back?

Usually yes. Use the official recovery flow (https://www.lacma.org/notice-data-security-incident) — it can verify you even when the attacker changed the email and password. Be patient and respond quickly to follow-ups so the case stays open.

Should I just make a new LACMA account instead?

Not until you've tried recovery. The old account keeps your history and contacts — and while the attacker controls it, it will be used to scam people who trust you. Recover it, or at minimum report it as compromised so LACMA can lock it, before you start over.

The hacker placed orders or drained gift cards on my LACMA account — now what?

Report the orders as unauthorized through LACMA's support, dispute any card charges with your bank, and check saved addresses and payment methods for ones the attacker added. Loyalty points and gift-card balances are a favorite target because people don't watch them like a bank account — screenshot balances and include them in the report.

Was LACMA hacked?

Yes. The museum's own notice says an unauthorised third party had access to a portion of its computer network from 7 to 11 July 2025, that the activity was detected on 11 July 2025, and that the investigation confirmed the intrusion in August 2025. The public notice describing it was published on 24 August 2026.

Why did LACMA wait a year to tell people about the data breach?

The museum's account is that identifying which files had been touched required an outside data-review firm whose initial results only came back in late February 2026, after which it worked on getting accurate contact details for the people involved. Whether that explains a thirteen-month gap is exactly what the proposed class action reported by ARTnews and Artforum in late August 2026 disputes.

Was my Social Security number exposed in the LACMA breach?

Possibly, but only your own letter can say. LACMA lists Social Security numbers among the data types that may have been accessed and states that the categories varied from person to person, so the site notice describes the whole pool rather than any individual. If no letter has reached you, the call centre on (844) 953-2547 is the way to ask.

Why did a museum have my medical information?

Health-insurance details and information such as provider name, diagnosis and treatment locations are the contents of employment benefits records rather than of a ticket purchase. SC Media reported that both customer and employee information was involved, and the medical fields point at the employee side of that.

Is LACMA offering free credit monitoring?

The notice on lacma.org does not offer a monitoring product; it recommends reviewing statements and free credit reports, placing a fraud alert or a security freeze, and using IdentityTheft.gov. BleepingComputer reported that the mailed letters include a year of identity-theft protection through Financial Shield with an enrolment deadline of 22 November, so the letter is what carries the offer.

Do I need to change my LACMA password because of the breach?

Nothing in the notice describes account credentials being taken, so a password change is not the fix for this. Doing it anyway costs nothing if you hold a MyLACMA account, but it will not protect a Social Security number or a driver's licence number, which is what this incident actually put at risk.

How do I stop my LACMA account being hacked again?

Three things close most of the doors: a unique password (a manager makes this painless), app-based two-factor authentication, and shrinking your exposed footprint — checking your email against known breach databases and removing your personal data from data-broker sites that attackers use to research targets.