Back to blog

Hall Pass: Moscone's Operator Confirms a Cyber Incident, and Your Venue Contract Just Became a Security Document

HB
Henrique B. 29 September 2026 · 5 min read
Hall Pass: Moscone's Operator Confirms a Cyber Incident, and Your Venue Contract Just Became a Security Document

Legends Global, the operator of San Francisco's Moscone Center, has confirmed a cybersecurity incident at the venue, and a ransomware group is claiming it walked off with files that include client event contracts and deposit records. The theft is unconfirmed. The organiser's question is already live: what does your venue hold about your event, and why?

What has actually been confirmed?

Only the incident itself. Legends told Skift Meetings on 28 September that it discovered the incident, contained it, and brought in outside cybersecurity specialists to investigate. The company also said Moscone is running normally with no business interruption, and that it could not say more while the investigation continues.

What Legends did not confirm matters just as much. It has not said who was responsible, whether any data left the building, or whether the incident is the same one a group called Settra is advertising. Treat everything below that line as a claim, not a finding.

What is the ransomware group claiming?

Settra listed Moscone on its leak site around 22 September, according to breach trackers including GalaxyWarden, which dates the claimed intrusion to 11 September and labels the listing an unverified extortion claim. As reported by Skift, the group says it holds roughly 250GB of material and has set a countdown to 2 October, when it threatens to publish.

The part that should make a planner put the coffee down is the list of client-facing documents the group says it has: event contracts, deposit records, cancellation correspondence and at least one client's certificate of insurance. If even half of that is real, some organisers' commercial terms are sitting in a folder with a ransom note stapled to it.

The honest caveat is that leak-site postings are a sales tool. A security specialist quoted by Skift points out that some of these listings contain genuine stolen data, while others inflate what was taken or recycle old material. One threat-intelligence firm has rated the Moscone listing as legitimate. Until Legends, a regulator filing or an independent investigator says otherwise, nobody outside the investigation knows which kind this is.

A venue that never receives your full attendee list cannot lose it. Data minimisation is the only security control that works even when somebody else's firewall does not.

Why are convention venues such an awkward target?

Because a single show pulls dozens of organisations through one building's systems. The venue team, the organiser, exhibitors, AV crews, caterers, decorators, security contractors and temporary staff can all touch shared files and networks in the fortnight around one event. Each handover is a copy, and every copy is a place data can leak from.

Moscone is not the first. Skift reported a ransomware group claiming an attack on Buffalo's convention centre in June. The pattern is that venues hold a lot of other people's paperwork, and extortion crews have noticed.

What this means for event organisers

The industry has spent decades teaching site inspections to ask about fire exits, loading docks, ceiling heights and accessibility. Data custody is the missing line on that checklist, and it is an analytics and reporting question as much as an IT one: you cannot measure risk in a data flow you have never drawn.

The alternative

Tired of Fee Announcements? Go Flat

eventcloud charges one subscription with no per-ticket fees, so platform news stops being budget news.

See pricing

So draw it. For your next contracted venue, list every document and dataset that crosses the boundary and ask four things of each.

  • Does the venue need it at all? A room plan needs headcounts and access requirements. It rarely needs names, emails and job titles for every delegate.

  • Who holds the master copy? Registration data should live in one system you control and be shared outward in the smallest slice that does the job, not emailed around as a full spreadsheet.

  • How long is it kept? Ask for a retention period in writing. Last year's delegate list sitting on a venue file server is pure liability for everyone.

  • How fast will they tell you? Put a breach notification window in the contract, and consider a financial consequence for missing it. An events lawyer quoted by Skift recommends exactly that.

The same questions apply to your hotel block partner, your badge printer and your registration platform. We wrote a longer guide on what data you actually need to collect at registration, and the short version is that every optional field is a future breach notice you have volunteered for.

What should you do this week if you use Moscone?

Do not wait for the 2 October countdown to find out what was in the folder. Ask your Legends account contact, in writing, whether your organisation's documents fall within the investigation's scope and when you will be told. Check what your contract says about notification. If you shared a certificate of insurance or payment details, brief your finance team so they can watch for invoice fraud dressed up as a venue update, which is exactly the kind of follow-on scam that leaked contracts make convincing.

If you hold attendee data under GDPR, it is also worth reading your own obligations as a controller, because a venue breach can still land on your desk. Our plain-English GDPR guide for registration data covers who owes whom a phone call.

The bigger shift: security is becoming a venue selection criterion

Expect this to show up in RFPs. Buyers already score venues on sustainability and accessibility, and a data-handling section is the obvious next column. Venues that can answer with a retention policy, a named security contact and a notification clause will win the comparison against venues that answer with a shrug. Organisers who ask first will be the ones who are not scrambling when the next leak site countdown starts.

Where eventcloud sits in this

Our view is the boring one: collect less, share less, and keep the master record somewhere you control. On eventcloud, ticket payments go through your own Stripe account rather than through us, and attendee lists export to Excel (.xlsx) when you choose to share them, so you decide what leaves and when. The price stays the same whether you register 500 people or 50,000, which means nobody is nudging you to hoover up more data to justify the bill. It is a per-user subscription, it is built for in-person events only, and it will not replace a proper conversation with your venue about what it keeps. See how registration works if you want the details.

Share this article Twitter LinkedIn
Stop paying to succeed

Run Your Next Event on Flat Pricing

Unlimited tickets, registrations and events. One price, no matter how big you grow.

Get in touch! Let's have a chat!