LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › The Metropolitan Entertainment & Convention Authority Listed by Dark Project Ransomware Group

HIGH severityUnverified claimHow we verify

The Metropolitan Entertainment & Convention Authority Listed by Dark Project Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 5, 2026

Occurred July 2026 · publicly disclosed August 5, 2026.

HIGH
Severity
1
Data types exposed
August 5, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Metropolitan Entertainment & Convention Authority was listed by the Dark Project ransomware group on August 05, 2026, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; anyone who has interacted with the authority should verify their exposure and take protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the The Metropolitan Entertainment & Convention Authority Listed by Dark Project Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account. Details go to your inbox.

The Metropolitan Entertainment & Convention Authority, the Omaha body that runs major public event venues, has been listed by the ransomware group Dark Project. Public reporting dated August 05, 2026 describes the listing and states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown.

According to the group’s claims, the incident involved the theft of more than 500 GB of confidential information, including customer data, important financial documents, and personal data of the organisation’s employees, with roughly 100,000 files described as unsecured. These details originate from the threat actor’s assertions and have not been independently confirmed in the available record. The episode matters because MECA handles information tied to public venues, events, staff, and patrons in Nebraska.

Breaking down the breach

What is known so far is limited to the public listing and the accompanying claims. Dark Project has named The Metropolitan Entertainment & Convention Authority as a victim and asserted that a successful cyberattack resulted in the exfiltration of internal files. The reported volume is more than 500 GB, said to encompass customer data, financial documents, and employee personal data, with about 100,000 files characterised as not secured. No independent confirmation of these figures, of the precise intrusion method, or of the exact timeline of compromise appears in the available facts. The count of affected individuals is explicitly unknown. In short, the incident is framed as a ransomware-related data theft whose scale and contents are described primarily through the group’s own statements rather than through a detailed official disclosure.

Inside Dark Project

Dark Project is a known ransomware operation that follows a familiar double-extortion pattern used by many contemporary groups: encrypting systems where possible while also stealing data and threatening to publish it on a leak site if demands are not met. Such groups typically advertise victims on dedicated sites, post samples or file counts to increase pressure, and rely on initial access through common vectors such as compromised credentials, phishing, or exposed remote services. Public reporting over time has associated Dark Project with claims against organisations across multiple sectors, though each listing remains a claim until corroborated. In this case, the group claims that MECA suffered a successful attack and that substantial volumes of internal material were taken; nothing in the provided facts confirms negotiations, payments, or the full extent of any encryption impact on operations.

About The Metropolitan Entertainment & Convention Authority

The Metropolitan Entertainment & Convention Authority, often referred to as MECA, is the organisation that manages public event venues in Omaha, Nebraska. Its facilities include the CHI Health Center, Charles Schwab Field, and The RiverFront. Established in 2000, it plays a central role in hosting large-scale events and supporting community engagement through those venues. Organisations of this type routinely handle ticketing and customer records, vendor and contractor information, employee personnel files, financial and accounting documents, and operational data tied to facility management and public events. A breach affecting such an entity is consequential because it can touch both the workforce that keeps venues running and the broader public who attend events, purchase tickets, or do business with the authority.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack. The threat actor’s claims go further, asserting that more than 500 GB of confidential information was stolen—specifically customer data, important financial documents, and the personal data of the organisation’s employees—and that about 100,000 files were not secured. Exact contents beyond those named categories remain unconfirmed by independent public detail. Entities that operate major public venues typically hold names, contact details, payment or ticketing-related records, employee identifiers and HR materials, contracts, and internal financial records. Whether any particular field or record set from those categories was present in the stolen volume cannot be verified from the information given; readers should treat the actor’s description as a claim pending further official clarification.

What's at stake

For individuals whose information may have been involved, the practical risks include unwanted contact, phishing or social-engineering attempts that reference real event or employment details, and potential misuse of personal or financial data if it was among the taken files. Employees could face elevated risk if personnel records were included; customers and patrons could face similar exposure if ticketing or contact data formed part of the haul. For the organisation, the stakes include operational disruption, the cost of investigation and remediation, possible regulatory or contractual obligations around notice, and erosion of trust among staff, vendors, and the public who rely on MECA venues. Because the number of people affected is unknown and the precise file inventory is unconfirmed, the full scope of harm cannot yet be measured; the concrete concern is that sensitive internal and personal material may now sit outside the organisation’s control.

If your data was in this breach

If you are an employee, vendor, or customer of The Metropolitan Entertainment & Convention Authority, treat the situation as a prompt to tighten basic hygiene rather than as confirmed proof that your specific records were taken. Monitor financial and email accounts for unusual activity, be wary of unexpected messages that reference Omaha venues or events, and consider placing fraud alerts with credit bureaus if you believe sensitive identifiers may have been involved. Change passwords on related accounts and enable multi-factor authentication where it is available. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Official updates from MECA, if and when they are issued, should be treated as the primary source for notification and next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyThe Metropolitan Entertainment & Convention Authority security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See The Metropolitan Entertainment & Convention Authority’s full breach history →

More recent breaches

Brainhunter Companies LLC. and Brainhunter Systems Ltd. Listed by Dark Project Ransomware GroupAugust 5, 2026Storer Transportation and Storer Coachways Listed by Dark Project Ransomware GroupAugust 5, 2026Reid Electric Service, Inc Listed by Dark Project Ransomware GroupAugust 5, 2026The Family Medicine Clinic Listed by Dark Project Ransomware GroupAugust 5, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the The Metropolitan Entertainment & Convention Authority Listed by Dark Project Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by dark-project — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram