Legends Global Confirmed Cybersecurity Incident

The San Francisco venue operator is investigating a potential data breach involving the Moscone Center.

Updated on Sept. 28, 2026 in Cybersecurity

Bold flat-color editorial illustration of a metallic server unit and data conduit, representing institutional cybersecurity and data security analysis.
Legends Global is investigating a cybersecurity incident involving the Moscone Center in San Francisco after a ransomware group claimed to have stolen internal data. AI Illustration. Upload story photo >

Live Poll

Do you trust event venues to keep your personal information and sensitive data secure?

Legends Global has confirmed a cybersecurity incident affecting the Moscone Center in San Francisco. A ransomware group known as Settra claims to have stolen 250GB of internal data, including sensitive personnel records.

Why it matters

The incident highlights ongoing threats from data-extortion groups targeting large public venues. Investigators are currently working to determine the scope of the potential data exposure.

The alleged theft involves approximately 250GB of data, including human resources documents, insurance policies, and tax records. These files reportedly contain Social Security numbers for more than 2,500 individuals.

The players

Legends Global

This company is the operator of the Moscone Center and is currently managing the investigation into the security incident.

Moscone Center

This is San Francisco’s primary convention and exhibition complex.

Settra

This is a data-extortion group that was first observed in June 2026.

The details

Legends Global has engaged third-party cybersecurity experts to investigate the breach after discovering the incident. Despite the claim by Settra, the Moscone Center remains fully operational.

Timeline

  1. Settra was first observed in June 2026.

  2. The cyberattack was reported on September 28, 2026.

  3. Settra threatened to release the data on October 2, 2026.

The Tech Race

The emergence of Settra mirrors the broader trend of ransomware-as-a-service groups targeting high-profile physical infrastructure. This incident follows a pattern where digital extortionists leverage stolen sensitive data to pressure organizations.

Employees and individuals associated with the venue should monitor their personal accounts for signs of identity theft due to the potential exposure of Social Security numbers. The Moscone Center remains open, meaning there are no expected disruptions to current events or services for visitors.

The takeaway

Organizations must prioritize the protection of employee tax and medical records to prevent long-term harm from data-extortion attempts. Proactive monitoring and immediate incident response remain critical for maintaining public trust during digital threats.

What happens next

The ransomware group Settra has indicated plans to release a full archive of the alleged stolen data on October 2, 2026.

Further reading

Learn more about the latest developments in Cybersecurity.

Source note: This article includes information reported by Skift Meetings.

Live Poll

Do you trust event venues to keep your personal information and sensitive data secure?