Data breach
Madison Square Garden Sports Corp.
- Records
- 9,793,091
- Breach date
- 12 June 2026Estimated
- Added
- 19 June 2026
What was exposed
5 types of data
- Email addresses9,793,091
- Names6,871,418
- Phone numbers5,664,601
- Street addresses4,941,228
- Dates of birth9,503
About this breach
ShinyHunters, a hacking group known for large-scale data extortion, has published a large cache of data it claims to have stolen from Madison Square Garden Sports Corp., the company that owns the New York Knicks and New York Rangers. According to reporting by 404 Media, the group set a June 15 ransom deadline and dumped roughly 45 GB of files on its leak site a day later after saying the company "failed to reach an agreement." The data, reviewed in part by 404 Media, includes customer emails sent to MSG, internal correspondence, and "Talent" files describing celebrities, former Knicks players, and coaches, with fields such as address, "claim to fame," "cost of talent," and internal risk ratings. ShinyHunters claims the dataset contains more than 26 million records. Our investigation team indexes this listing at 9,793,091 rows and estimates the attack occurred around June 12, 2026; the group itself said the intrusion happened on June 5. Three class-action lawsuits have since been filed against MSG's companies in federal court in Manhattan, according to The New York Times.
Breach Timeline
June 5, 2026: ShinyHunters says it hacked Madison Square Garden systems, according to a group spokesperson quoted by 404 Media.
June 12, 2026: ShinyHunters announces the theft and demands a ransom, threatening to publish more than 26 million records, per lawsuits described by The New York Times.
June 15, 2026: The group's ransom deadline expires without payment, according to multiple news reports.
June 16, 2026: ShinyHunters publishes the data on its leak site. The same day, a lawsuit is filed in the U.S. District Court for the Southern District of New York alleging visitor data was exposed through MSG's surveillance and facial recognition systems.
Late June 2026: Three class-action lawsuits are pending against Madison Square Garden Entertainment and Madison Square Garden Sports Corp., per The New York Times.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, names, phone numbers, street addresses, and dates of birth. Email addresses appear in nearly all 9.79 million rows we indexed, while names, phone numbers, street addresses, and birthdays are present in smaller, overlapping subsets.
Not every individual is affected by every type of data listed here.
Reporting by 404 Media, which reviewed a sample of the published files, additionally found customer support emails, internal corporate documents, and structured "Talent" profiles that include home addresses, appearance costs, and contact details for representatives. Whether payment card data or Social Security numbers are in the dump remains unconfirmed.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is phishing. With names, email addresses, phone numbers, and street addresses in hand, scammers can craft convincing messages that reference MSG, the Knicks, or ticket purchases. Watch for texts or emails asking you to verify payment details, reset a password, or click a link about a refund.
The exposure of home addresses and internal risk ratings also raises more serious safety and privacy concerns, particularly for the high-profile individuals named in the talent files. A negligence lawsuit filed after the dump argues MSG failed to protect information gathered through its facial recognition program. Because identity thieves combine data from multiple breaches, anyone affected should assume their details may circulate in scam campaigns for years.
What Is Madison Square Garden Sports Corp. Doing in Response?
The company has not issued a detailed public statement about the breach. The New York Times reported that Madison Square Garden Entertainment and Madison Square Garden Sports Corporation declined to comment. As of June 23, 2026, no public notification letters or regulator filings had surfaced in our review. The litigation filed in New York may force fuller disclosure later.
What Should You Do If You Were Affected?
Be skeptical of any message referencing MSG, ticket purchases, or account problems; do not click links or share payment details.
Use a unique, strong password for your MSG or Ticketmaster-linked accounts and enable multi-factor authentication where available.
Monitor financial accounts and credit reports for unfamiliar activity; consider a credit freeze if your address was exposed.
Delete or ignore unsolicited calls and texts that cite personal details; legitimate companies will not pressure you for information by phone.
In the news
- 404 Media: Hackers Publish Knicks and Madison Square Garden Data Online404media.co (opens in a new tab)
- The New York Times: Customers Sue Madison Square Garden Over Hacking of 26 Million Recordsnytimes.com (opens in a new tab)
- BankInfoSecurity: Breach Roundup — ShinyHunters Leaks 26M MSG Recordsbankinfosecurity.com (opens in a new tab)
- Secureworld: ShinyHunters Dumps MSG Sports Data After Knicks Championshipsecureworld.io (opens in a new tab)
