Small triangle design

Madison Square Garden Breach: What Dealerships, Non Profits, and SMBs Must Learn Now

August 12, 2026

The Madison Square Garden Entertainment (MSG) breach is one of the most consequential ShinyHunters operations to date not because it hit a sports empire, but because it exposed the exact weaknesses that dealerships, non‑profits, and mid‑market organizations struggle with every day.

ShinyHunters claims to have stolen 26 million+ customer and corporate records, including PII, internal documents, and not something usually compromised, facial‑recognition surveillance logs and internal threat‑assessment dossiers. When MSG missed the June 15 ransom deadline, the group published 45GB of data online, triggering a federal class‑action lawsuit.

Even if your organization doesn’t run an NBA arena, the attack pattern and organizational failures behind this breach map directly onto the risks facing any organization that collects and maintains customer/client private data.

What Actually Happened

ShinyHunters claimed access to 26M+ customer and corporate records, including PII and internal MSG documents. The group issued a June 15 extortion deadline and, when MSG did not pay, leaked 45GB of data, including:

Facial‑recognition logs

Internal risk profiles of celebrities

Customer complaints about misidentification

Background‑check data and internal threat assessments

The breach occurred around June 5, with data leaked June 16, immediately after the Knicks’ NBA Finals win, maximizing public pressure. ShinyHunters’ claims are consistent with their recent pattern of large‑scale data theft and extortion campaigns.

Why This Breach Matters to your organization

MSG is a massive enterprise but the weaknesses exploited are the same ones attackers use against dealerships, schools, non‑profits, and mid‑market organizations:

Over‑collection and long‑term retention of sensitive data

MSG stored biometric data, risk profiles, internal assessments, and customer complaints in the same systems. When attackers got in, they got everything. Your business likely does the same with:

  • Driver’s license scans
  • Credit applications
  • Employment files
  • CRM exports
  • Vendor‑shared data

Weak vendor and system segmentation

ShinyHunters frequently exploits SaaS platforms, CRM integrations, and identity systems the same attack surface dealerships rely on for DMS, CRM, telematics, and OEM portals.

Extortion‑first attacks (not ransomware)

ShinyHunters increasingly uses data theft + public shaming, not encryption. This means backups don’t save you. Paying doesn’t guarantee they delete your data. They’re goal is public exposure and reputational damage.

High‑value PII concentration

Any organization with large customer lists, loyalty programs, or donor databases is a target not because of money, but because of data density.

The “So What?”  If you collect it, you must protect it — or stop collecting it

MSG’s biggest failure wasn’t the breach; it was retaining years of biometric and surveillance data that didn’t need to exist. For your organization, consider purging old credit apps, delete expired donor lists, remove old CRM exports, stop storing driver’s license images indefinitely. Data minimization is the cheapest cybersecurity control you can implement.

Your SaaS and vendor ecosystem is your biggest attack surface

ShinyHunters has repeatedly targeted SaaS platforms (Canvas, Salesforce‑linked incidents, etc.). You are vulnerable through your DMS, CRM, OEM portals, Marketing platforms, finance portals and third-party service schedulers. Do you know what data they collect, how that data is secured and what safety protocols they have in place to protect against unauthorized access to your data?

Surveillance, biometrics, and “extra” data are liabilities

Businesses often use security cameras, license plate readers, facial-recognition programs, telematics data and customer tracking tools. If you use these tools, be sure to document why you use them and your data retention policies. Restrict access to this data, disclose its collection and usage and encrypt ALL at rest and in transit data! Ask yourself the question: “Do we need to collect this information?” and “Do we need to hold onto it?” Delete everything you are not legally required to keep!

5 Immediate Actions You Should Take Now:

 

Purge unnecessary data (especially PII and biometrics)

Delete:

  • Old credit apps
  • Expired donor lists
  • CRM exports older than 12 months
  • Driver’s license scans after verification
  • Old employee files
  • Surveillance logs beyond 30–60 days

This reduces breach impact by 80%+ in most organizations.

 

Enforce MFA everywhere — especially for vendors and remote access

ShinyHunters frequently uses credential theft and session hijacking. Require MFA for:

  • DMS
  • CRM
  • OEM portals
  • Email
  • VPN
  • Remote support tools
  • Finance portals

 

Segment your systems and restrict vendor access

Create separate access zones for:

  • DMS
  • CRM
  • HR/payroll
  • Finance
  • Security systems
  • Marketing platforms

Vendors should never have broad access across systems.

 

Update your incident‑response plan for extortion‑only attacks

Include:

  • Pre‑approved legal language
  • Customer notification templates
  • A2C escalation contacts
  • Law enforcement contacts
  • A decision tree for ransom/extortion scenarios

 

Conduct a 30‑minute “ShinyHunters Readiness Check”

A2C clients can run this internally:

  • Do we know where our sensitive data lives?
  • Do we know who has access?
  • Do we have MFA everywhere?
  • Do we have a vendor‑access inventory?
  • Do we have a plan for extortion‑only attacks?

If any answer is “no,” you have the same weaknesses MSG had. The team at Accelerate2Compliance can help turn your “no” into “Yes.”

 

Closing Thoughts

ShinyHunters didn’t target MSG because it’s a sports empire, they targeted it because it had high‑value data, weak segmentation, and over‑retention. Does this describe your organization? This breach is not a sports‑industry problem. It’s a data‑governance problem, a vendor‑risk problem, and a modern extortion problem.

Sources:

ShinyHunters published 45GB of Madison Square Garden data, including facial recognition surveillance records

ShinyHunters Claims Massive Madison Square Garden Sports Data Breach Affecting 26 Million Records: Dark Web Recent Claims + Video – UNDERCODE NEWS

Was New York Knicks owner breached? ShinyHunters say so | Cybernews


Speaker Profile Picture of Matthew Vatter

Matt Vatter

Chief Compliance Officer, Accelerate2Compliance

Small triangle design

Why A2C?

Compliance is an incredibly complicated topic, but our solution is the opposite of complicated: it’s just simple. We take the complexities of information security compliance and simplify them, so you can know what you need to do, do it efficiently, then get back to doing what you do best. You’ll get everything you need from us, and that’s all – you will not be paying for extras you DON’T need. We know what we’re doing. As you begin your information security compliance journey with A2C, you can rest assured you’ll be headed down the road to compliance.

Is A2C Right for You?

Find Out With This Quick Q&A

Let's Talk

Still need help? Let’s talk! You’ll learn how easy our product is to use and scale, and how we can save you time, money, and stress.

To top