The Metropolitan Entertainment and Convention Authority Data Breach

Alleged

Ransomware claim involving The Metropolitan Entertainment and Convention Authority.

Published: Aug 5, 2026 Dark Project
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
The Metropolitan Entertainment and Convention Authority
Industry
Hospitality
Threat Actor
Dark Project
Date of Incident
Aug 5, 2026

Executive Summary

The Metropolitan Entertainment & Convention Authority, a hospitality organization based in the United States, was identified on August 5, 2026, as a victim of the Dark Project ransomware group. This discovery was made through SOCRadar’s Dark Web Monitoring service. The authority functions within the venue and events management sector, a public-facing role often linked with municipal operations. This listing marks the sole hospitality-related entry among Dark Project’s recent victim claims. In the 60 days preceding this listing, Dark Project claimed 17 other victims. The group has predominantly targeted the manufacturing, healthcare, and transportation sectors. Their primary victim countries include the United States, the United Kingdom, and the Philippines. The Metropolitan Entertainment & Convention Authority’s inclusion is notable as its sector, venue and events management, falls outside the group’s typically targeted verticals, making it the most sectorally distinct victim in the current batch of claims. Recent US-based victims like Mile Bluff Medical Center, Reid Electric Service, Inc, Rocky Mount Recyclers, and The Family Medicine Clinic highlight the group’s activity in the region.

Technical Analysis

SOCRadar’s analysis of The Metropolitan Entertainment & Convention Authority against its stealer-log telemetry returned no records for the domain omahameca.org within the queried dataset. It is crucial to understand that a null result does not confirm the organization is unaffected by a compromise. The query’s scope was limited to a paginated sample, potentially excluding other relevant data. Furthermore, credentials harvested under alternate corporate domains or personal email aliases, common for public authorities with multiple branded online presences, would not be captured by a lookup on the primary corporate domain alone. Such gaps are particularly pertinent for organizations like The Metropolitan Entertainment & Convention Authority, which manage separate venue and event-specific domains that may accumulate staff credential exposure. For ransomware operations, infostealer-harvested credentials represent a well-documented pathway for initial access. Threat actors or initial access brokers frequently acquire valid credentials from underground marketplaces. These credentials are then used to gain unauthorized access to systems, including Microsoft 365, VPNs, or remote-access portals, paving the way for ransomware deployment. The absence of direct evidence in this specific query does not preclude such a scenario. It is possible that credentials may have existed in other data feeds not included in this analysis, might have been used and subsequently rotated before being indexed, or were harvested using personal email addresses associated with the corporate domain. Consequently, CTI teams are advised to continue monitoring for potential threats and conduct proactive credential hygiene checks, rather than interpreting a null query as definitive proof of an uncompromised state.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.