LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › moscone.com Listed by Settra Ransomware Group

HIGH severityUnverified claimHow we verify

moscone.com Listed by Settra Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 22, 2026
moscone.com Listed by Settra Ransomware Group

Occurred September 2026 · publicly disclosed September 22, 2026.

HIGH
Severity
September 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

moscone.com was listed by the Settra ransomware group on September 22, 2026. Individuals whose data may have been held by the site should review their accounts and consider protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 22, 2026, the ransomware group Settra listed moscone.com on its leak site, presenting the listing as evidence of a cyber incident tied to the Moscone Center web presence. Public detail is limited: the number of people affected is unknown, the types of data supposedly involved are not disclosed, and neither the organisation nor a regulator has publicly confirmed the claim as of writing. What exists so far is an extortion-style posting and a brief promotional blurb from the group, not an independently verified inventory of events or files.

Listings of this kind matter because they are designed to pressure organisations and to alarm customers, partners, and staff. They do not, by themselves, prove that systems were entered, that files left the network, or that any particular record is circulating. Readers should treat the Settra material as an unverified accusation and weigh practical precautions only on a conditional basis—if personal or business data were involved—rather than as confirmation that it was.

What is being claimed

Settra has listed moscone.com on its leak site. The reported headline frames the entry as a listing by the Settra ransomware group. A short accompanying summary on the listing side uses marketing-style language associated with the venue—“We Create Unforgettable Experiences”—and refers to “What ASM Global Hides Backstage at Moscone Center,” with a fragmentary “PROLOGUE” line. That text reads as attacker framing, not as a technical report.

The facts available for this write-up do not include a claimed intrusion date, a method of access, a ransom demand amount, a file count, a sample set of documents, or a verified count of affected individuals. People affected are recorded as unknown. Data types named as exposed are not disclosed. Timing beyond the September 22, 2026 reporting of the listing is undisclosed. In plain terms: the public record described here is the existence of the listing and the group’s own wording, not a completed forensic account.

As of writing, moscone.com’s operator has not publicly confirmed the claim. Until a company statement, regulatory notice, or other independent confirmation appears, the responsible description remains that Settra claims an association between its activity and moscone.com, and that the claim is unproven in the open sources reflected in these facts.

Inside Settra

Settra operates in the style common to ransomware and extortion crews that maintain leak sites. Such groups typically claim to have encrypted or copied data, then threaten publication unless payment or other conditions are met. Public pressure is part of the model: naming a victim, posting teaser language, and implying that sensitive material will follow are standard tactics meant to hasten negotiation and to damage reputation even before any files are shown.

Well-documented patterns across this ecosystem include double-extortion narratives (encryption plus alleged theft), countdown-style pressure, and selective release of samples when crews choose to escalate. Those patterns describe how groups like Settra generally present themselves; they are not proof of what occurred in any single case. For this listing, the only victim-specific content reflected in the facts is the leak-site entry for moscone.com and the brief backstage-themed blurb. No additional claims by Settra about this victim—such as technical pathways, insider involvement, or a catalog of stolen databases—are provided in the material at hand, and none should be invented.

A leak-site listing establishes that a group wants the public and the named organisation to believe a breach occurred. It does not establish chain of custody, authenticity of any later files, freshness of the data, or whether material was recycled from older incidents. Readers and journalists should separate the theatre of the listing from verified incident response findings.

Who is moscone.com?

moscone.com is the public web presence associated with the Moscone Center, a major convention and events complex in San Francisco. Large civic and commercial venues of this type are commonly operated under professional management brands; public references often connect Moscone operations with ASM Global, a firm known for managing arenas, convention centres, and similar facilities. The site and the venue brand support event discovery, booking pathways, visitor information, and business relationships with exhibitors, organisers, vendors, and attendees.

Organisations in this sector sit at a crossroads of public events and private commercial arrangements. They typically coordinate schedules, contracts, credentials, logistics, and customer communications at scale. A credible incident affecting systems behind such a site could, in principle, touch corporate contacts, event participants, and operational partners. That potential reach is why a leak-site claim draws attention—even when the claim remains unconfirmed and the exact systems involved are unnamed.

Consequential does not mean proven. The significance of the Settra listing is that it targets a recognisable public venue brand and implies “backstage” material. The listing does not demonstrate what infrastructure was involved, whether moscone.com itself was the entry point, or whether any claim about ASM Global or Moscone operations is accurate.

What data was at risk

The facts state that data types named as exposed are not disclosed. It is therefore not possible to assert that any specific category—customer lists, payment details, employee records, contracts, badge data, or internal documents—was taken. The attacker’s marketing language about what is “hidden backstage” is not an inventory.

If files were taken from an organisation in this sector, firms running major convention centres typically hold some mix of business contact information, event and exhibitor records, vendor and contractor details, internal operational documents, and, depending on systems, account or credential-related data for staff and partners. Some environments also process payment or registration flows through affiliated platforms. Those are sector norms, not findings about this listing.

Because the Settra entry does not name exposed data types in the facts provided, any discussion of risk must stay conditional. Exact contents remain unconfirmed. No count of records is known. No verification has been offered in the material summarised here that samples match live Moscone or ASM Global systems.

The real-world impact

For individuals, the practical risk depends entirely on whether personal information was actually copied and whether it later appears in usable form. If contact data or account-related information were involved, people could face targeted phishing that references real events, venues, or employers; impostor messages that cite Moscone-related details sound more plausible than generic spam. If financial or identity-adjacent data were ever implicated—again, unconfirmed here—monitoring for fraud would become more important. At present, affected-person counts are unknown, so scale cannot be stated.

For the organisation, a public extortion listing can disrupt trust among exhibitors, attendees, and partners even before facts are settled. Event businesses rely on confidence in operations and on smooth handling of contracts and logistics. Reputation harm from an unverified claim is real as a communications problem; it is not the same as a confirmed data loss. Legal, contractual, and regulatory duties—if a breach were later confirmed—would turn on jurisdiction, data types, and notice laws; those questions are premature while the incident itself remains an unconfirmed listing.

What a leak-site post does establish is intent to coerce. What it does not establish is the integrity of the claim, the freshness of any data, or negligence on the part of the named business. Analysis that leaps from a listing to conclusions about engineering, detection, or culture would be speculation dressed as fact.

If your data was involved

If you believe your information may be tied to Moscone Center, ASM Global, or related event activity, treat the situation as precautionary until official confirmation exists. Be wary of unexpected emails, texts, or calls that cite the venue, a past event, refunds, badges, or “breach assistance,” and verify any request through official channels you already trust rather than links in unsolicited messages. Prefer unique passwords and multi-factor authentication on email and work accounts so that a single leaked password, if one ever appears, does less damage. Monitor financial accounts for unfamiliar charges if you have ever paid for services connected to the venue or its events.

If you are a vendor, exhibitor, or employee, follow your organisation’s security guidance and watch for social-engineering attempts that reference contracts or backstage operations. Public detail on this listing remains limited; the company has not publicly stated the incident as of writing, and Settra’s claims should not be read as a notice that your data is definitely out.

As a simple additional check, readers can run a free exposure scan of their email address to see whether that address has already appeared in known breach datasets unrelated or related to past incidents—useful hygiene when any high-profile listing surfaces, and still not proof about this specific claim.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companymoscone.com security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See moscone.com’s full breach history →

More recent breaches

lakebeverage.com Listed by Settra Ransomware GroupSeptember 22, 2026universalautogroup.com Listed by Settra Ransomware GroupSeptember 22, 2026gregjoneslaw.com Listed by Settra Ransomware GroupSeptember 22, 2026naturesplus.com Listed by Settra Ransomware GroupSeptember 17, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the moscone.com Listed by Settra Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by settra — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram