Legends Global Confirmed Moscone Center Cyberattack

The data-extortion group Settra claimed it accessed 250GB of internal venue records.

Updated on Sept. 28, 2026 in Cybersecurity

Isometric editorial illustration of a modern glass and steel convention center facade, representing enterprise cybersecurity infrastructure.
Legends Global is investigating a data-extortion attack on San Francisco's Moscone Center that potentially compromised personal records of 2,500 individuals. AI Illustration. Upload story photo >

Live Poll

Do you trust event venues to keep your personal information and sensitive data secure?

Legends Global confirmed a cybersecurity incident affecting the Moscone Center in San Francisco. The ransomware group Settra asserts it has stolen 250GB of data, including records for over 2,500 individuals.

Why it matters

This incident places the personal information of thousands at risk and tests the resilience of critical event infrastructure. The situation highlights the ongoing threat posed by data-extortion groups to high-traffic public venues.

The extortion group claims to hold 250GB of files, including employee tax records, medical documents, and insurance policies. Whether these figures represent a complete or partial data set remains unverified.

The players

Legends Global

An operator of large-scale event venues that manages the infrastructure and administrative systems for the Moscone Center.

Settra

A data-extortion group that has been active since June 2026 and focuses on stealing sensitive records for ransom.

Moscone Center

San Francisco's primary convention complex that handles high-volume administrative data and large-scale public events.

The details

Legends Global initiated an investigation by hiring third-party cybersecurity experts to assess the breach. Upon discovery, the venue operator implemented containment measures to stop unauthorized access and secure internal systems. The Moscone Center remains fully operational despite the ongoing investigation.

Timeline

  1. June 2026: The Settra group was first observed publicly.

  2. September 28, 2026: News of the Moscone Center incident was published.

  3. October 2, 2026: Settra has threatened to release the full archive of allegedly stolen files.

The Tech Race

This incident follows the broader trend of extortion groups targeting venue operators to leverage stolen HR and medical records. It highlights a recurring race between facility security teams and bad actors who increasingly target administrative internal networks.

Individuals whose information was handled by the Moscone Center should monitor their financial and medical statements for suspicious activity. While the venue remains operational, the potential release of employee and administrative data necessitates heightened caution regarding identity theft.

The takeaway

The primary risk now is the potential public release of sensitive personal documents on October 2, 2026. Readers should monitor future updates from Legends Global regarding whether their specific data was contained in the alleged breach.

What happens next

Settra has explicitly stated that it plans to release the alleged data archive on October 2, 2026.

Further reading

For broader context on current threats to regional infrastructure, see Cybersecurity.

Source note: This article includes information reported by Skift Meetings.

Live Poll

Do you trust event venues to keep your personal information and sensitive data secure?