
S0E23. The LA County Museum of Art breach that took a year to unravel
LACMA’s year-long breach disclosure delay and what it says about incident response Jess Hebenstreit and Jake Williams break down a Los Angeles County Museum of Art data security incident that raises big questions about breach timelines, notification delays, and response ownership. They focus on what the disclosure says, what it leaves unsaid, and why the cleanup process may have taken far longer than it should have. In this episode, they examine the gap between initial detection, timeline validation, data review, and eventual notification. They also unpack why the kind of data exposed suggests employee and benefits records, and why that matters for both legal exposure and response logistics. Key topics The breach timeline looks unusually long Jess and Jake note that LACMA says it detected suspicious activity on July 11, 2025, but did not publish the disclosure until August 24, 2026. They question how it took weeks to confirm the intrusion window and then months more to complete the data review. The delay in scoping the incident raises red flags Jake points out that the investigation later narrowed the third party’s access to July 7 through July 11. They discuss how incident teams can get stuck chasing false leads in logs, but still say this timeline feels slow. Data review appears to have dragged on The disclosure says the initial data review results arrived in late February 2026. Jess and Jake interpret that as a sign of weak data governance, poor vendor management, or both. The affected data suggests employee and benefits records The potentially exposed data includes full names, dates of birth, Social Security numbers, government ID numbers, financial account numbers, payment card data, health insurance information, and limited medical details. Jess argues that this pattern looks like employee data, possibly tied to a self-funded health plan. Notification logistics seem inconsistent Jake questions why the organization spent months trying to obtain “accurate contact information” before notifying impacted people. He notes that breach notification rules generally do not wait for perfect contact data before state reporting obligations begin. A class action lawsuit seems likely Jess says she expects litigation, and Jake agrees. They also suggest state attorney general investigations are likely. The response may have suffered from leadership turnover Jess thinks a change in leadership or responsibility may have disrupted the response. Jake agrees that handoffs, missing context, or people being removed mid-incident can create major problems. They believe outsourcing the data review was the right move, but too late Jake explains why identifying impacted records is harder than it sounds, especially with inconsistent name formats, spellings, and duplicate records. Both agree this kind of work should be handled by a firm that does breach review every day. Cyber insurance and breach counsel likely shaped the response They debate whether the organization had cyber insurance and how that would have affected the handling of the case. Jake explains that cyber claims usually involve upfront costs and reimbursement later, which can slow response work. The human cost of a broken incident response Jess closes by saying she feels bad for the responders who had to deal with the mess. Jake advises responders to keep notes, assume they may be deposed later, and remember that the organization will not protect them in enforcement actions. Timestamps 00:00 - Breach Please intro and the show’s no-nonsense mission 01:33 - LACMA data security incident enters the conversation 01:50 - Why the disclosure timeline is so hard to believe 03:18 - What the timeline says about detection and scoping 06:01 - Late February 2026 data review results 07:57 - Why “accurate contact information” is a weak explanation 08:52 - Why a lawsuit and state investigations seem likely 09:27 - The exposed data and why it looks like employee records 10:54 - A Reddit post suggesting notifications were already going out 12:12 - Possible leadership change during the response 13:37 - When even counsel decides the incident is too messy 15:31 - Whether cyber insurance was involved at all 17:04 - How cyber claims actually get paid 18:38 - Procurement problems or failed in-house review? 20:21 - Why identifying impacted people is much harder than it sounds 22:36 - Why outsourcing the review was probably necessary 23:35 - Why state reporting obligations still matter even if mailing is slow 24:04 - Sympathy for the responders caught in the middle 25:02 - Why responders should document everything now 25:57 - Final reminder: organizations do not protect employees in enforcement actions 26:11 - Outro and closing sign-off