READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

ShinyHunters Claims 45GB of Madison Square Garden Customer Data, Published Days After Knicks Championship

ShinyHunters Claims 45GB of Madison Square Garden Customer Data, Published Days After Knicks Championship
The hacking and extortion group ShinyHunters published what it claims are millions of records stolen from Madison Square Garden, including customer personal information and data referencing Knicks players and coaches. The dump landed days after New York's first NBA championship since 1973. MSG has not publicly confirmed the breach.

What Was Released

The hacking group ShinyHunters published a trove of files it claims were stolen from Madison Square Garden, according to reporting by 404 Media. The alleged dump spans 45 gigabytes across multiple files and purportedly contains millions of customer records, along with references to Knicks players and coaches.

A sample reviewed by 404 Media included at least one file listing names of "talent" connected to the Knicks organization. The full contents of the dump have not been independently verified, and MSG has not issued a public statement confirming or denying a breach as of June 20, 2026.

Who Is ShinyHunters

ShinyHunters is not a new name. The group has claimed responsibility for a string of high-profile intrusions in recent months, according to Wired. Victims it has publicly named include Instructure, the education technology firm behind Canvas, which Wired reports caused disruption across thousands of schools. The group also claimed attacks on photography company Kodak and a European human rights organization.

The group's pattern is consistent: breach, threaten, then publish if demands go unmet or for publicity. Whether MSG paid, negotiated, or simply got published regardless is not established by available reporting.

Timing and Context

The data was released not long after the Knicks won the NBA championship, their first title since 1973. Whether the timing was deliberate—to maximize embarrassment or press coverage—is unknown. It would not be the first time a threat actor has timed a release for maximum public attention.

Wired has previously reported on Madison Square Garden's own extensive use of surveillance technology, including facial recognition deployed at its venues. An organization that runs one of the more aggressive fan-surveillance operations in American sports allegedly had its own customer data lifted and posted publicly.

What the Data Could Mean for Customers

If the records are authentic, the people most directly affected are MSG customers whose personal information may now be circulating. Millions of records is a meaningful number. Anyone who has purchased tickets, signed up for MSG accounts, or otherwise given the company personal data has reason to watch for phishing attempts and credential-stuffing attacks using any exposed email addresses or passwords.

Fans who attended games, concerts, or other MSG events should treat any unsolicited contact claiming to be from MSG with skepticism and consider whether reused passwords need to be changed.

The Strongest Counterpoint

The most important caution here is one that applies to every ShinyHunters claim: the data has not been independently verified as genuine or as originating from MSG systems. Hacking groups routinely overstate breach scope, repackage old data, or publish compilations sourced from prior leaks to claim credit for something they did not actually do. Until MSG or an independent security firm confirms the authenticity and origin of these files, "ShinyHunters claims" is the accurate framing, not "MSG was breached." 404 Media reviewed a sample, but a sample is not verification of 45GB.

ShinyHunters' track record of verified, real breaches means the claim cannot be dismissed. The group has produced confirmed stolen data before.

What Happens Next

Madison Square Garden has not announced whether it is investigating, whether it has notified potentially affected customers, or whether it has been in contact with federal law enforcement. If New York State's SHIELD Act applies—and a breach of customer personal information from a company headquartered in New York would almost certainly trigger it—MSG is legally required to notify affected residents "in the most expedient time possible" once a breach is reasonably determined to have occurred.

MSG needs to either confirm this breach and notify customers, or produce evidence that the published data is fabricated. Silence is not a data-security strategy, and customers deserve a clear answer.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredHackers Claim to Leak Stolen Madison Square Garden Data