Multiple federal class action suits, and a defamation suit, have already been filed in relation to the breach.

 

What happened

According to 404 Media, an independent journal, hackers recently published stolen data from Madison Square Garden (MSG) and the Knicks. The attack was claimed by the group ShinyHunters, which has quickly grown infamous for numerous attacks with high victim counts. According to an X post, ShinyHunters claimed to have over 26 million records of data, including personally identifiable information (PII) and internal corporate data. ShinyHunters threatened MSG on June 12th, 2026, demanding that the company reach out to the threat group by June 15th, or else the data would be leaked. On June 16th, the hackers published the records on their leak site, stating that they had failed to reach an agreement with MSG.

 

Going deeper

In a report from Databreach.com, which tracks breaches and the data they contain, the data stolen by ShinyHunters included names, dates of birth, email addresses, phone numbers, and street addresses. According to 404 Media, some Knicks-related data was also included, with unique information like “claim to fame,” “cost of talent,” and contact information of players or their representatives. The New York Times also noted breach data included internal emails and other corporate information.

 

What was said

According to 404 Media, in ShinyHunters message to MSG, the malicious group said, “It’s very simple. When you pay, your data is deleted, and you move on with your life. When you don’t pay us, you get posted here, among other things.”

When MSG did not respond to ShinyHunters’ initial contact attempts, the group said, “This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision.” The referenced “annoying” digital problems have not been identified at this time.

The New York Times contacted Josephine Wolff, professor of cybersecurity policy at Tufts University, who shared that she believed ShinyHunters hoped to embarrass MSG to force a payout. Wolff noted that the real money is in the ransom payment, not necessarily in getting a payout from selling the data online. The majority of the data, while tied to high-profile individuals, would not be a big money maker on the dark web. In general, Wolff described the data as having a “lower risk to customers,” but it would still be reasonable to question what someone might do with the information if they were to find it.

 

What’s next

Following the breach, Madison Square Garden Entertainment and Madison Square Garden Sports Corporation, the two parent companies, have already become the subject of multiple class action lawsuits, which were all filed in the Southern District of New York. The first class action lawsuit was filed on behalf of Carlos Avalos from Nassau County, N.Y., who had attended a Dua Lipa concert in September and has now had their data accessed.

MSG has filed a suit of defamation against Wired Magazine, according to USA today, for certain claims made about the data. Wired claimed that some celebrity data was opinion-based, citing some celebrities were stated as being riskier to host than others, and that some celebrities would not be hosted. According to Wired, the data also labeled certain people as LGBTQIA. The lawsuit against Wired claims that the data was “cherry-picked” to “manufacture a false narrative portraying MSG as targeting the LGBTQIA community for discriminatory purposes.”

 

The big picture

Data breaches like these bring mass attention to cybersecurity practices in the United States. While breaches at MSG may bring a wide audience, breaches at other, smaller organizations, are happening daily. When small amounts of information, like dates of birth or email addresses, are combined with other data pulled from breaches, it can create a more complete victim profile, leading to increased risk of fraud or theft. Every breach counts, whether it’s at a healthcare facility, or an entertainment venue, as more and more people find themselves on the dark web. No breach happens in true isolation; over time, breaches against a single person accumulate, and that’s when data security becomes a higher threat. Every organization, big and small, with highly sensitive data or data considered less sensitive, should be careful of their security practices.

 

FAQs

Who are other victims of ShinyHunters?

ShinyHunters currently has an estimated victim count of 132, including companies like Instructure (Canvas), Kodak, JCPenney, Ralph Lauren, DentaQuest, Medtronic, and other business and healthcare organizations.

 

Why do different outlets say the breach included different data?

Outlets vary on what they report, likely because there was so much data in this breach. With 26 million records, there is simply a lot of information. Different outlets likely found different points relevant or interesting. It’s likely that the breach included everything listed by each outlet, although it’s possible some data points were cherry-picked, like MSG claims Wired Magazine did.