Threat Intelligence

Speed Art Museum Data Leak

Speed Art Museum Data Leak

Victim:

Speed Art Museum, The Speed Art Museum, formerly known as the J.B. Speed Memorial Museum and commonly called “the Speed” by locals, is Kentucky’s oldest and largest art museum. Founded in 1927, it is located on Third Street in Louisville, adjacent to the University of Louisville’s Belknap campus. The Speed Art Museum generated $9.6 million in revenue.

About the data breach:

Speed Art Museum data leak:

On September 23, 2025, the threat actor group “INC RANSOMWARE” claimed responsibility for a data breach at the Speed Art Museum. The exposed data includes project reports, auction estimates, personal service contracts, employee records, Social Security numbers, and internal museum management documents, raising serious concerns over data security and privacy.

Speed Art Museum Data Leak

Samples:

Speed Art Museum Data Leak

The above screenshot contains the museum auction estimation process, It covers key factors influencing estimates and the importance of accurate valuation in museum fundraising.

Speed Art Museum Data Leak

The screenshot above shows the Project Activity Report for the Speed Art Museum. It highlights current and upcoming exhibitions, Statements of Activity (SOAs), and future projections, offering insights into the museum’s operational and strategic planning.

Speed Art Museum Data Leak

The above screenshot highlights the museum’s personal service contract, revealing key details such as names, addresses, and account information, emphasizing the importance of data privacy and security.

Speed Art Museum Data Leak

The above screenshot contains sensitive employee personal details, including name, job title, date of birth, Social Security number (SSN), address, phone number, and dependent information. It emphasizes the critical need for protecting employee data and maintaining privacy standards.

Speed Art Museum Data Leak

The above screenshot offers an overview of the museum’s annual budget and revenue, providing insights into its financial planning, funding sources, and overall economic impact on cultural operations programming.

Key Recommendations to Prevent Cyber Incidents

  • Deploy Advanced Monitoring (Gurucul SIEM):
    Implement Gurucul’s next-gen SIEM with UEBA to detect abnormal user and entity behavior, ransomware indicators, and unauthorized access early.
  • Strengthen Identity & Access Controls:
    Enforce MFA, restrict access to sensitive data, and regularly review user permissions—especially for accounts handling contracts and employee records.
  • Encrypt and Protect Sensitive Data:
    Ensure personal information, financial documents, and internal records are encrypted both at rest and in transit to reduce exposure in case of a breach.
  • Keep Systems Fully Patched and Updated:
    Regularly update software, servers, and applications to close vulnerabilities commonly exploited by ransomware groups.
  • Enhance Endpoint & Network Security:
    Use EDR tools, segment critical systems, and block lateral movement to prevent attackers from spreading across the environment.
  • Increase Employee Cyber Awareness:
    Train staff to recognize phishing attempts, suspicious emails, and social engineering tactics—common entry points for ransomware attacks.
Advanced cyber security analytics platform visualizing real-time threat intelligence, network vulnerabilities, and data breach prevention metrics on an interactive dashboard for proactive risk management and incident response