Madison Square Garden Sports data incident and publication

A data-theft incident followed by public publication of Madison Square Garden and Knicks-related records. A directly reviewed published sample and a later verified HIBP email corpus associated with the incident.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

A data-theft incident was followed by public publication of Madison Square Garden Sports and Knicks-related records. [1][3]

Impact

A directly reviewed published sample and a later verified HIBP email corpus associated with the incident. [1]

Documented data types include:

  • Names — Names listed for HIBP’s verified corpus. [1]
  • Customer service records — Customer service records listed for HIBP’s verified corpus; 404 Media separately observed customer emails. [1]
  • Contact information — Email addresses, phone numbers, and physical addresses listed for HIBP’s verified corpus. [1]

A cited record reports 9,796,738 records (Unique email addresses represented in HIBP’s verified corpus; not a company-confirmed number of people, customers, staff, accounts, files, or total rows; as of 2026-06-24). [1]

404 Media directly observed that Madison Square Garden data had been published online for public download. [3]

404 Media reported that the published data included emails between customers and Madison Square Garden. [3]

Timeline

  1. Documented event

    HIBP BreachDate and date claimed by an attacker spokesperson to 404 Media; not a victim-confirmed detection or intrusion timestamp.

    [1]
  2. Public disclosure

    Date 404 Media published its direct sample review.

    [3]
  3. Public disclosure

    Date HIBP added the Madison Square Garden Sports corpus; not a victim-notification date.

    [1]
  4. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • ShinyHunters

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

404 Media reported that a low-level employee was called and tricked into allowing access to MSG systems. The sample reviewed by 404 Media contained files mentioning specific sports teams and Knicks-related personalities, including address, claim-to-fame, talent-cost, and some contact fields. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2][3]