Events and Rooms

Moscone's operator runs 450 venues and 20,000 events a year. Your cancellation correspondence is sitting in somebody else's file server.

The claimed haul reads less like a venue's IT problem and more like a filing cabinet belonging to every company that booked the place.
October 1, 2026
A convention center whose facade is filing cabinet drawers, one hanging open and spilling contracts into the street

Settra, a ransomware group with 93 claimed victims since June, posted moscone.com to its leak site on 22 September. Six days later Legends Global, which operates San Francisco's Moscone Center, confirmed to Skift Meetings that it had contained a cybersecurity incident with outside help. The venue is fully operational, and chief communications officer Stacey Escudero said that "protecting the security of our systems and the data entrusted to us is a top priority."

Settra's listing puts the haul at 249GB. By the group's own account that includes Social Security numbers for more than 2,500 people, employee tax and medical records, insurance policies, and further down the list, event contracts, deposit records, cancellation correspondence and client certificates of insurance. None of that is confirmed. Legends Global has not verified any of it, and a leak site listing is an extortion tactic before it is evidence.

Read the second half of that list again anyway.

The interesting part is not the ransomware

Employee records turning up in a breach is the most ordinary thing in security. The unusual entries are the commercial ones. Event contracts. Deposit records. Cancellation correspondence.

Those are not really the venue's documents. They are documents an events team negotiated, signed and then stopped thinking about, sitting on a third party's file server under whatever retention policy that party happens to keep. If the claims hold up, somebody now has the rate a company agreed to, how much it put down, and the date it got nervous and asked about cancelling.

Every events team in B2B describes in-person as the channel with no data trail. The trail exists. It is filed under somebody else's name.

450 venues, 20,000 events, one vendor

Legends Global is not a regional operator. The leak site does not even use that name: Settra headlined its listing with ASM Global, the company Legends acquired and folded into a September 2025 rebrand. Under the current name it runs more than 450 venues across six continents, roughly 20,000 events a year and more than 165 million guests. The Los Angeles and Pennsylvania convention centers sit on the same list as Moscone.

That is the shape of the exposure. An events team signs with a venue and inherits a supplier sitting underneath a large share of its own calendar. It is the same concentration story the industry called good news when private equity started buying trade shows, which we covered when the meeting count became the KPI and the organizer owned the count. Consolidation makes one relationship easier to manage and one failure far more expensive.

The industry found out from the extortion site

Security trackers put the alleged intrusion at 11 September and the listing at 22 September. The first trade coverage ran on 28 September. Take the most generous reading, where Legends contained it quickly and Settra is inflating the haul, and the sequence still holds: event marketers whose contracts are named in that listing learned about it from a criminal's advertising, not a notification.

Joshua Grimes, an attorney who works with planners, told Skift the fix is contractual: assume a breach may occur and write notification windows into the venue agreement. That is correct, unglamorous and almost nobody has done it. Venue negotiations are about room blocks, attrition and force majeure. Nobody arrives at that table with a data processing addendum.

Ask a field marketing lead where their leads are and they will tell you about the CRM. Ask who processed the registration list, and how long the venue keeps the delegate manifest, and the answer is a pause.

This runs alongside the complaint RevOps has made for years, that most of what happens in a room never reaches the CRM at all. Both are true at once, and the combination is the part worth sitting with. The room is under-instrumented for the company paying for it and thoroughly instrumented for everyone that company hired.

"Every events team I talk to can tell me their cost per lead," says Pieter Limburg, CEO of Mobilo. "Almost none of them can tell me which four companies are holding that lead right now."

So the one channel B2B still calls offline throws off a paper trail detailed enough to extort somebody over, and the only organization that cannot produce it on demand is the one that wrote the cheque.

The question you should be able to answer in sixty seconds

Every other channel arrived with this question pre-answered. Email has a sending platform with a named data processing agreement. Ads have a platform contract. The CRM has a security page procurement already read, and when a vendor there is breached the notification is a clause, not a news story. In-person is where that discipline never landed, because the spend runs through marketing and the data never looks like data. It looks like contracts and a badge scanner somebody rented.

Here is the test. Take your largest event of 2026 and give yourself sixty seconds to name every organization currently holding a copy of the attendee list, plus the deletion clause in each of those contracts. Most teams will not clear it.

That is going to change, and not because events teams get more interested in security. It changes because the first time an attendee list surfaces on a leak site with a logo attached, the question moves from IT to procurement and gets asked before the contract is signed. The teams who can answer it in 2027 will find it is the cheapest credibility they have ever bought. The teams who cannot will answer it anyway, on somebody else's schedule.

Undivided Attention is powered by Mobilo.

Every events team I talk to can tell me their cost per lead. Almost none of them can tell me which four companies are holding that lead right now.

Pieter Limburg, CEO, Mobilo

  1. Skift Meetings, Cyberattack at Moscone Center Puts Event Data Security in the Spotlight, 28 September 2026. Legends Global confirmation, the Escudero statement, the claimed file categories and the Joshua Grimes recommendation.
  2. ransomware.live, Settra listing for moscone.com. Listing discovered 22 September 2026 at 16:50 UTC, estimated intrusion 11 September 2026, 249GB claimed.
  3. Falcon Internet, Settra Ransomware: 93 Victims in Four Months Using Your Own VPN Against You, September 2026.
  4. TSNN, World's Largest Venue Management Company Gets a New Name: Legends Global, 9 September 2025. The 450 venues, 20,000 events and 165 million guests figures, and the named venues.
  5. Undivided Attention, Private equity spent $5.1 billion on trade shows this year. Meetings booked is the KPI, and the organizer owns the count, 11 September 2026.

Every figure attributed to Settra is a claim made by the group during an extortion attempt. Legends Global has not confirmed the volume or the file categories.