Legends Global Confirmed Cybersecurity Incident
The San Francisco venue operator is investigating a potential data breach involving the Moscone Center.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust event venues to keep your personal information and sensitive data secure?
Legends Global has confirmed a cybersecurity incident affecting the Moscone Center in San Francisco. A ransomware group known as Settra claims to have stolen 250GB of internal data, including sensitive personnel records.
Why it matters
The incident highlights ongoing threats from data-extortion groups targeting large public venues. Investigators are currently working to determine the scope of the potential data exposure.
The alleged theft involves approximately 250GB of data, including human resources documents, insurance policies, and tax records. These files reportedly contain Social Security numbers for more than 2,500 individuals.
The players
Legends Global
This company is the operator of the Moscone Center and is currently managing the investigation into the security incident.
Moscone Center
This is San Francisco’s primary convention and exhibition complex.
Settra
This is a data-extortion group that was first observed in June 2026.
The details
Legends Global has engaged third-party cybersecurity experts to investigate the breach after discovering the incident. Despite the claim by Settra, the Moscone Center remains fully operational.
Timeline
Settra was first observed in June 2026.
The cyberattack was reported on September 28, 2026.
Settra threatened to release the data on October 2, 2026.
The Tech Race
The emergence of Settra mirrors the broader trend of ransomware-as-a-service groups targeting high-profile physical infrastructure. This incident follows a pattern where digital extortionists leverage stolen sensitive data to pressure organizations.
Employees and individuals associated with the venue should monitor their personal accounts for signs of identity theft due to the potential exposure of Social Security numbers. The Moscone Center remains open, meaning there are no expected disruptions to current events or services for visitors.
The takeaway
Organizations must prioritize the protection of employee tax and medical records to prevent long-term harm from data-extortion attempts. Proactive monitoring and immediate incident response remain critical for maintaining public trust during digital threats.
What happens next
The ransomware group Settra has indicated plans to release a full archive of the alleged stolen data on October 2, 2026.
Further reading
Learn more about the latest developments in Cybersecurity.
Source note: This article includes information reported by Skift Meetings.
Live Poll
Do you trust event venues to keep your personal information and sensitive data secure?










