Madison Square Garden Sports Data Breach (June 2026)
Days after the Knicks won the NBA Finals, ShinyHunters published data taken from Madison Square Garden Sports, and Have I Been Pwned verified almost 10 million email addresses covering customers and staff.
- Organization
- Madison Square Garden Sports
- Sector
- Media and entertainment
- Country
- United States, NY
- Incident date
- June 5, 2026
- Disclosed
- June 16, 2026
- Records affected
- 9.8 million
- Attack type
- Undisclosed
- Threat actor
- ShinyHunters
- Status
- Confirmed
- Email addresses
- Names
- Phone numbers
- Physical addresses
- Customer service records
- The intrusion, according to a spokesperson for the group quoted by 404 Media
- ShinyHunters publishes the data for download; 404 Media reviews a sample
- Have I Been Pwned loads 9.8 million verified email addresses
What Happened
On June 16, 2026, the ShinyHunters extortion group published data it said was stolen from Madison Square Garden, the New York company behind the Knicks, the Rangers and the arena itself, for anyone to download. 404 Media reviewed a sample and found files about specific sports teams and Knicks-related personalities with fields such as address, "claim to fame" and "cost of talent," a list of talent that included former players and coaches with risk ratings, and emails between customers and MSG. A pop-up on the group's site put the extortion in plain terms: pay and the data is deleted, do not pay and it is posted.
A spokesperson for the group told 404 Media the intrusion happened on June 5. The publication landed days after the Knicks won the NBA Finals, which is why it drew far more attention than a typical leak. Have I Been Pwned analyzed the published data and, on June 24, loaded 9,796,738 unique email addresses spanning staff and customers, alongside personal, employment and customer relationship information.
MSG has not described how the attackers got in, so the attack type is recorded as undisclosed. Lawsuits were filed against the company within days of the publication.
What was Exposed
Email addresses, names, phone numbers, physical addresses and customer service records: the correspondence between ticket holders and the company. The customer service records are the unusual element. Knowing what someone complained about, which seats they hold and how the company replied is the raw material for a convincing "we are following up on your case" message.
For staff, the exposure is employment information, which supports impersonation of the company to its own people.
What to do if you are Affected
The tells in the messages that follow a breach like this are in what phishing looks like, and the general order of operations is in what to do after a data breach.
What is not Known Yet
How the attackers got in, whether payment card data was involved anywhere in the corpus, and what MSG's own notice to customers says. The report will be updated when the company or a regulator filing adds to the record.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.