
Leading U.S. event management company Legends International said the data security incident it suffered in November compromised the sensitive personal and financial information of its customers, including over 8,000 residents of Texas.
Headquartered in New York, Legends International is a global sports and entertainment services company offering a wide range of services including venue planning, sales, partnerships, hospitality and more.
In a data security incident notice filed with Attorney Generals of Texas and Massachusetts, Legends said that on November 9, it identified unauthorised activity in its internal network. The event management company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to take the affected systems offline, terminated the unauthorised access and notified relevant law enforcement authorities about the incident.
The investigation revealed that “certain Legends files had been accessed and acquired during the unauthorised activity.”
The compromised data included customers’ names, dates of birth, Social Security Numbers, driver’s license numbers, government-issued ID numbers such as passports & state ID cards, account numbers, credit and debit card numbers, medical Information, health Insurance Information, and more.
While the company did not share the total number of affected individuals, it informed the Texas Attorney General’s office that it has so far identified at least 8,060 Texans who were affected by the incident.
“Prior to the incident, Legends had a number of cybersecurity measures in place across the environment. As we brought systems back online, we took a series of steps to further strengthen our security controls,” the company said.
While Legends found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered two years of complimentary identity protection and credit monitoring services through Experian Identity Works to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on Legends. The company also did not share details on who was behind the attack, how much data was compromised, or whether it has received a ransom demand.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543