Pacific Symphony notified the California Attorney General of a cybersecurity incident on August 21, 2025, where an unauthorized third party accessed part of its IT network. The organization terminated access and engaged forensic experts. Investigation determined the actor had the opportunity to extract data, including full names and other personal information. No evidence of actual misuse was found. Affected individuals were offered 12 months of credit monitoring.