
Settra, a ransomware group with 93 claimed victims since June, posted moscone.com to its leak site on 22 September. Six days later Legends Global, which operates San Francisco's Moscone Center, confirmed to Skift Meetings that it had contained a cybersecurity incident with outside help. The venue is fully operational, and chief communications officer Stacey Escudero said that "protecting the security of our systems and the data entrusted to us is a top priority."
Settra's listing puts the haul at 249GB. By the group's own account that includes Social Security numbers for more than 2,500 people, employee tax and medical records, insurance policies, and further down the list, event contracts, deposit records, cancellation correspondence and client certificates of insurance. None of that is confirmed. Legends Global has not verified any of it, and a leak site listing is an extortion tactic before it is evidence.
Read the second half of that list again anyway.
Employee records turning up in a breach is the most ordinary thing in security. The unusual entries are the commercial ones. Event contracts. Deposit records. Cancellation correspondence.
Those are not really the venue's documents. They are documents an events team negotiated, signed and then stopped thinking about, sitting on a third party's file server under whatever retention policy that party happens to keep. If the claims hold up, somebody now has the rate a company agreed to, how much it put down, and the date it got nervous and asked about cancelling.
Every events team in B2B describes in-person as the channel with no data trail. The trail exists. It is filed under somebody else's name.
Legends Global is not a regional operator. The leak site does not even use that name: Settra headlined its listing with ASM Global, the company Legends acquired and folded into a September 2025 rebrand. Under the current name it runs more than 450 venues across six continents, roughly 20,000 events a year and more than 165 million guests. The Los Angeles and Pennsylvania convention centers sit on the same list as Moscone.
That is the shape of the exposure. An events team signs with a venue and inherits a supplier sitting underneath a large share of its own calendar. It is the same concentration story the industry called good news when private equity started buying trade shows, which we covered when the meeting count became the KPI and the organizer owned the count. Consolidation makes one relationship easier to manage and one failure far more expensive.
Security trackers put the alleged intrusion at 11 September and the listing at 22 September. The first trade coverage ran on 28 September. Take the most generous reading, where Legends contained it quickly and Settra is inflating the haul, and the sequence still holds: event marketers whose contracts are named in that listing learned about it from a criminal's advertising, not a notification.
Joshua Grimes, an attorney who works with planners, told Skift the fix is contractual: assume a breach may occur and write notification windows into the venue agreement. That is correct, unglamorous and almost nobody has done it. Venue negotiations are about room blocks, attrition and force majeure. Nobody arrives at that table with a data processing addendum.
Ask a field marketing lead where their leads are and they will tell you about the CRM. Ask who processed the registration list, and how long the venue keeps the delegate manifest, and the answer is a pause.
This runs alongside the complaint RevOps has made for years, that most of what happens in a room never reaches the CRM at all. Both are true at once, and the combination is the part worth sitting with. The room is under-instrumented for the company paying for it and thoroughly instrumented for everyone that company hired.
"Every events team I talk to can tell me their cost per lead," says Pieter Limburg, CEO of Mobilo. "Almost none of them can tell me which four companies are holding that lead right now."
So the one channel B2B still calls offline throws off a paper trail detailed enough to extort somebody over, and the only organization that cannot produce it on demand is the one that wrote the cheque.
Every other channel arrived with this question pre-answered. Email has a sending platform with a named data processing agreement. Ads have a platform contract. The CRM has a security page procurement already read, and when a vendor there is breached the notification is a clause, not a news story. In-person is where that discipline never landed, because the spend runs through marketing and the data never looks like data. It looks like contracts and a badge scanner somebody rented.
Here is the test. Take your largest event of 2026 and give yourself sixty seconds to name every organization currently holding a copy of the attendee list, plus the deletion clause in each of those contracts. Most teams will not clear it.
That is going to change, and not because events teams get more interested in security. It changes because the first time an attendee list surfaces on a leak site with a logo attached, the question moves from IT to procurement and gets asked before the contract is signed. The teams who can answer it in 2027 will find it is the cheapest credibility they have ever bought. The teams who cannot will answer it anyway, on somebody else's schedule.
Undivided Attention is powered by Mobilo.
Every events team I talk to can tell me their cost per lead. Almost none of them can tell me which four companies are holding that lead right now.
Pieter Limburg, CEO, Mobilo
Every figure attributed to Settra is a claim made by the group during an extortion attempt. Legends Global has not confirmed the volume or the file categories.