READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

MSG Kept Secret Files on Gay Celebrities, Surveillance Critics, and Fans Who Complained Online

MSG Kept Secret Files on Gay Celebrities, Surveillance Critics, and Fans Who Complained Online
A criminal hack of Madison Square Garden exposed an internal database tagging hundreds of celebrities with risk scores, LGBTQIA labels, and 'DO NOT HOST' flags. Separate files show MSG compiled detailed dossiers on privacy activists who publicly criticized the company's facial recognition program. Three class-action lawsuits have been filed over the breach.

What the Hack Revealed

Earlier in June 2026, a criminal hacker collective called ShinyHunters published a 45GB cache of data stolen from Madison Square Garden Entertainment. The breach exposed 26 million customer records, including contact details and biometric data, according to CNET.

Buried inside that trove: an internal database MSG called its "talent" file, containing 39,539 entries tracking celebrities, business figures, politicians, and media personalities. According to Wired, roughly 400 of those entries carried explicit risk scores — ranging from low to high — and some carried the label "LGBTQIA." Others were flagged "DO NOT HOST."

Fat Joe, a self-described Knicks superfan who publicly defended MSG owner Jim Dolan during scrutiny of the team's NBA Finals security practices, is listed in the database as "medium risk," according to Wired. He publicly praised Dolan as "the greatest team owner in the game." His file apparently reflects a different internal assessment.

Other courtside regulars flagged with risk scores include Edie Falco, Mark Ronson, John Turturro, and Tracy Morgan, per Wired.

The Social Media Surveillance Operation

The risk scores aren't random. A source with direct knowledge of MSG's security operations told Wired that a "medium" or "low" risk label means a celebrity "has done something in the publicity world, the social media world, that has caught the attention of the wrong people."

Wired had already documented, in a separate April investigation, that MSG's security team runs social media sweeps specifically targeting people who criticize Dolan or MSG management. That operation extended to ordinary fans. In one internal message reviewed by Wired, an MSG security staffer described dispatching local law enforcement to visit a 14-year-old in Colorado over a single critical tweet: "They scared the crap out of some 14 year old kid in Colorado."

The talent database spans entries from December 2020 through early June 2026 and makes repeated reference to "SM concerns" — social media concerns — as a tracking category.

The Facial Recognition Dossiers

A separate document in the hacked data, titled "Facial Recognition Activists.docx," takes the surveillance operation in a different direction entirely. According to CNET, which drew on reporting by 404 Media, the file compiles detailed background information on three specific individuals who have publicly opposed MSG's facial recognition practices:

  • Adam Schwartz, privacy litigation director at the Electronic Frontier Foundation
  • Albert Fox Cahn, founder of the Surveillance Technology Oversight Project (STOP)
  • Evan Greer, director of Fight for the Future

The dossier includes their personal contact information, backgrounds, social media posts, and follower counts.

Schwartz told CNET: "Biometric surveillance like face recognition is especially dangerous, because we can't change our faces and we show them wherever we go."

Fight for the Future's official statement said MSG is "incapable of safeguarding the data it collects." That criticism has obvious weight now, given that the company's surveillance files on its own critics got leaked to the public.

A representative for MSG Entertainment did not respond to CNET's request for comment.

The Case for MSG's Surveillance Practices

The company has publicly stated that its facial recognition system exists to identify genuine security threats, and that is a legitimate operational concern for a venue that hosts tens of thousands of people per event. Large public venues face real threats. Identifying barred individuals, tracking credentialed guests, and maintaining VIP access lists are standard security practices. A private entertainment company categorizing its high-profile guests is not, on its face, illegal. The problem MSG faces is not that it built a security database. It's that the database reached well beyond security into political and identity-based profiling, that it tracked critics who posed no physical threat, and that the company failed to protect any of it.

The Legal Fallout

MSG now faces three class-action lawsuits stemming from the breach, according to the New York Times. The suits allege the company failed to adequately protect sensitive information and seek damages for the breach itself and for the resulting risks of identity theft and privacy harm.

The exposure of biometric data is particularly serious. Unlike a password or credit card number, a face cannot be reissued.

The Open Question

New York State's Biometric Privacy Act imposes specific requirements on entities that collect and store biometric identifiers. Whether MSG's practices, and its data security failures, trigger liability under that law is something the three pending class actions will test. The lawsuits also raise an unresolved question none of the companies involved have answered publicly: if a venue's facial recognition database is hackable, what legal obligation does it have to the millions of people whose faces it scanned without their explicit knowledge?

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredMadison Square Garden Kept a List of Gay Celebrities
unknown
news.backboxMadison Square Garden Kept a List of Gay Celebrities - BackBox News
unknown
cnetMadison Square Garden Targeted Privacy Activists and Surveillance Critics - CNET