Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity NewsArenas / Stadiums / Leagues / Entertainment

Hackers Exposed Knicks, Madison Square Garden Data

By Jordyn Alger, Managing Editor
Madison Square Garden
Colynary Media via Unsplash
June 25, 2026

On June 12, the cybercriminal group ShinyHunters announced it had hacked Madison Square Garden data. The group asserted that if a ransom was not paid, it would expose more than 26 million records. 

On June 16, the group published the records after the organization failed to make an agreement with the ransomware gang. 

Exposed data includes: 

  • Customer records
  • Internal emails 
  • Celebrity contacts 
  • Corporate data 

A June 23 report from the New York Times reveals multiple class action lawsuits have already been filed against the company. 

Security Leaders Weigh In

Nathaniel Jones, Vice President, Security & AI Strategy and Field CISO at Darktrace:

The reported Madison Square Garden incident should be viewed in the context of a much wider pattern of cyber risk across professional sport. Our recent research found that 84% of professional sports organizations experienced a cyber incident in the past 12 months, and 57% were hit more than once. That tells us this is not an isolated issue for a single team, venue, or league.

Sports organizations are attractive targets because they combine valuable data, high-profile individuals, complex vendor relationships, and digital systems that are expected to work under intense public pressure. A breach does not need to disrupt a game to cause damage. Exposed data, compromised executive accounts, or trusted communications used for fraud can quickly create financial and reputational consequences. As sport becomes more digital and connected, cybersecurity needs to be treated as a business priority. Organizations need visibility and control across the systems, identities, data, and partners that keep the business running.

Matthieu Chan Tsin, Senior Vice President, Resiliency Services at Cowbell:

The latest cyber event involving Madison Square Garden must be used as a reminder that even companies with large budgets are not immune to cyber-attacks. By refusing to pay a ransom, MSG took a valiant stand, however, may now be liable to incur a different type of damage.

Shane Barney, Chief Information Security Officer at Keeper Security:

ShinyHunters has demonstrated repeatedly that the most valuable data in an organization is rarely the data an organization thinks to protect most carefully. Ticketing systems, customer support platforms and internal operational databases are not typically where security investment is concentrated, but they are where years of customer correspondence, internal profiles and sensitive business information quietly accumulate. That is the gap this group consistently finds and exploits.

The question worth asking after an incident like this is not just how the attacker got in, but what they were able to reach once inside. Operational systems that are governed as administrative infrastructure rather than as high-value targets often lack the access controls that more obviously sensitive environments receive. When access is not scoped to least privilege, monitored for anomalous behavior or time-limited, the blast radius of any compromise expands well beyond what the initial foothold would suggest. Centralizing access governance, enforcing least privilege across every system that touches customer or employee data and building in continuous monitoring are the controls that close that gap. For organizations watching this unfold, the more pressing question is whether they would have detected a similar exfiltration before the attacker announced it publicly. If the answer is uncertain, that is the gap worth addressing first.

Anyone who has purchased tickets, contacted MSG customer support or attended events at MSG venues in recent years should assume their contact information may be among the exposed data. That means being alert to phishing emails and text messages that appear to reference your MSG account or recent purchases, particularly any that ask you to click a link, verify payment information or reset a password. Using a password manager to ensure your MSG account credentials are unique and not reused across other sites limits your exposure significantly. Enabling multi-factor authentication wherever it is available adds another layer of protection. If you receive any communication that references personal details you did not expect a sender to know, treat it with caution and verify through official channels before taking any action.

KEYWORDS: data breach data breach response lawsuit ransom reputational risks

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Healthcare supplies

3 Healthcare Breaches in Quick Succession Raises Concerns

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man driving

150M Driver’s Licenses Exposed, Security Experts Discuss

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Police lights

Family of Fatally Shot Security Guard Seeking Answers


AlertMedia sponsored webinar

Events

September 24, 2026

Physical Security Under the Microscope: The Top 4 Gaps That Fail Compliance Audits

LIVE: September 24, 2026 at 2 PM EDT Security and compliance reviews of physical security devices tend to fail for the same reasons. Learn the gaps that trip up these reviews, and why they're getting harder to ignore as scrutiny on connected devices increase. 

September 30, 2026

When ICE Visits Your Hospital

LIVE: September 30, 2026 at 2 PM EDT This webinar will discuss practical frameworks for developing policies, training staff, and coordinating with legal, compliance, and executive leadership before an enforcement action occurs.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Madison Square Garden Security Guards Win $1.3 million Settlement

    See More
  • Man in glowing mask

    Dark Web Forum Breached, Hackers Exposed

    See More
  • Stacks of files

    600,000 sensitive files exposed by data broker SL Data Services

    See More

Related Products

See More Products
  • surveillance.jpg

    Surveillance, Privacy and Public Space

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing