Skip to content
Cyber Security Firms

Madison Square Garden Sports Data Breach (June 2026)

Days after the Knicks won the NBA Finals, ShinyHunters published data taken from Madison Square Garden Sports, and Have I Been Pwned verified almost 10 million email addresses covering customers and staff.

Disclosed Updated
Organization
Madison Square Garden Sports
Country
United States, NY
Incident date
June 5, 2026
Disclosed
June 16, 2026
Records affected
9.8 million
Attack type
Undisclosed
Threat actor
ShinyHunters
Status
Confirmed
Data exposed
  • Email addresses
  • Names
  • Phone numbers
  • Physical addresses
  • Customer service records
Timeline
  1. The intrusion, according to a spokesperson for the group quoted by 404 Media
  2. ShinyHunters publishes the data for download; 404 Media reviews a sample
  3. Have I Been Pwned loads 9.8 million verified email addresses

What Happened

On June 16, 2026, the ShinyHunters extortion group published data it said was stolen from Madison Square Garden, the New York company behind the Knicks, the Rangers and the arena itself, for anyone to download. 404 Media reviewed a sample and found files about specific sports teams and Knicks-related personalities with fields such as address, "claim to fame" and "cost of talent," a list of talent that included former players and coaches with risk ratings, and emails between customers and MSG. A pop-up on the group's site put the extortion in plain terms: pay and the data is deleted, do not pay and it is posted.

A spokesperson for the group told 404 Media the intrusion happened on June 5. The publication landed days after the Knicks won the NBA Finals, which is why it drew far more attention than a typical leak. Have I Been Pwned analyzed the published data and, on June 24, loaded 9,796,738 unique email addresses spanning staff and customers, alongside personal, employment and customer relationship information.

MSG has not described how the attackers got in, so the attack type is recorded as undisclosed. Lawsuits were filed against the company within days of the publication.

What was Exposed

Email addresses, names, phone numbers, physical addresses and customer service records: the correspondence between ticket holders and the company. The customer service records are the unusual element. Knowing what someone complained about, which seats they hold and how the company replied is the raw material for a convincing "we are following up on your case" message.

For staff, the exposure is employment information, which supports impersonation of the company to its own people.

What to do if you are Affected

The tells in the messages that follow a breach like this are in what phishing looks like, and the general order of operations is in what to do after a data breach.

What is not Known Yet

How the attackers got in, whether payment card data was involved anywhere in the corpus, and what MSG's own notice to customers says. The report will be updated when the company or a regulator filing adds to the record.

Sources

  1. Have I Been Pwned: Madison Square Garden Sports
  2. 404 Media, Hackers Publish Knicks and Madison Square Garden Data Online, June 16, 2026
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →