Last updated 2 weeks ago
Madison Square Garden Sports, a sports and entertainment company, suffered a data breach in June 2026 as part of a ShinyHunters 'pay or leak' extortion campaign. The breach exposed approximately 9.8 million unique email addresses belonging to staff and customers, along with extensive personal, employment, and customer relationship information. The disclosure date is June 2026, though the internal discovery date is not specified.
The attack was carried out by the threat actor group ShinyHunters, who initially demanded payment and subsequently published the alleged data after the extortion attempt failed. The exact initial access vector is not detailed, but the breach involved unauthorized access to systems containing sensitive personal and business data. The exposed data types include email addresses, personal details, employment records, and customer relationship information, though specific hashing or encryption status is not mentioned.
No further post-incident details are available in the article, such as regulatory notifications, litigation, or remediation milestones.
ShinyHunters extortion campaign; data published after failed payment
Madison Square Garden Sports' breach underscores the need for robust access controls and monitoring to detect unauthorized access early, especially for organizations holding large volumes of personal and employment data. The involvement of a known extortion group like ShinyHunters highlights the importance of proactive threat intelligence and incident response planning to mitigate the impact of data exfiltration and extortion attempts.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor