Legends Global Investigates Moscone Center Cyberattack
The venue operator is investigating a security breach as a hacking group threatens to leak 250GB of files.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust event venues to keep your personal information and sensitive data secure?
Employees and others linked to the Moscone Center are facing potential data exposure after a cybersecurity incident was confirmed at the facility. A ransomware group named Settra claims to have accessed the venue's internal records and is threatening to publish them publicly.
Why it matters
The breach raises significant security concerns for thousands of individuals, as the stolen files reportedly contain sensitive Social Security numbers and medical records. Residents and staff currently await further confirmation regarding the scope of the incident.
A hacking group claims to hold 250GB of data, including Social Security numbers for 2,500 people. Legends Global has not confirmed if these figures are accurate or the total volume of records affected.
The players
Legends Global
The company that operates the Moscone Center in San Francisco.
Moscone Center
The city's primary convention facility located in San Francisco.
Settra
A data-extortion group that claims to have stolen 250GB of files from the venue.
The details
Legends Global, which operates the Moscone Center, has engaged third-party cybersecurity experts to investigate the intrusion and took immediate steps to contain the threat. While the venue remains fully operational, the extortion group known as Settra has threatened to release a full archive of the stolen data on October 2, 2026. The investigation into what specific employee and insurance records were accessed remains ongoing.
Timeline
June 2026: Settra was first observed as a data-extortion group.
September 28, 2026: News of the cybersecurity incident was published.
October 2, 2026: Settra plans to release the alleged data archive.
Across the Bay
This incident follows a documented trend of activity from the Settra group, which has been active since June 2026. The situation mirrors other data-extortion efforts that have targeted regional infrastructure and private operators throughout the Bay Area.
While the Moscone Center remains open, those associated with the venue should monitor their personal accounts for suspicious activity. Settra has threatened to release the alleged files on October 2, 2026.
The takeaway
Affected individuals should stay alert for signs of identity theft given the nature of the information involved. Keep watch for official updates from Legends Global following the October 2, 2026, deadline set by the extortion group.
Further reading
You can find more coverage on regional digital security threats in our Cybersecurity section.
Source note: This article includes information reported by Skift Meetings.
Live Poll
Do you trust event venues to keep your personal information and sensitive data secure?






