ShinyHunters, one of the most prolific data extortion groups operating today, has published 45 gigabytes of stolen data from Madison Square Garden Entertainment Corp. (MSG Entertainment) after the company refused to pay a ransom. The breach, which the attackers announced in mid-June 2026, exposed records for up to 26 million individuals — and the data is not your typical username-and-password dump. Leaked files include security reports, internal threat-assessment dossiers, VIP profiles, and — most alarmingly — data tied to MSG’s controversial facial recognition surveillance program, which the company has used for years to screen guests across its New York City venues.
ShinyHunters set a ransom deadline of June 15, 2026. When MSG declined to pay, the group published the data publicly on June 16. This marks the second major breach to hit MSG Entertainment this year: in February, the company disclosed a separate incident attributed to the Clop ransomware group — that breach, stemming from an Oracle eBusiness Suite vulnerability exploited between August and December 2025, exposed Social Security numbers and personal details for roughly 131,000 individuals. Multiple class-action lawsuits have now been filed against MSG, with plaintiffs alleging negligence in data protection and failure to notify affected customers in a timely manner.
The breadth of biometric and surveillance-adjacent data in this breach is what sets it apart. MSG’s facial recognition program has already drawn significant legal scrutiny in New York; having that data — including threat-assessment profiles compiled on guests — available to any criminal who grabs the leak makes this substantially worse than a standard credential breach.
Sources
- TechRepublic — Madison Square Garden Hack: 26M Records
- SecureWorld — ShinyHunters Dumps MSG Data
- TEISS — MSG Faces Class Action After 26M Record Breach
Commentary
The presence of facial recognition data and guest threat-assessment profiles in this leak deserves more attention than it’s getting. MSG collected surveillance intelligence on thousands of people who simply attended concerts and sporting events — the breach doesn’t just compromise personal contact details, it exposes behavioral and security profiling information that was never meant to be public. Victims of this breach face risks that go beyond standard identity fraud: their threat-classification status (benign or otherwise) is now available to anyone.
ShinyHunters has now been linked to 14 of the 37 confirmed mega-breaches recorded in the first half of 2026. The group’s consistent willingness to publish data when ransoms go unpaid should recalibrate how organizations calculate the expected cost of non-payment. Traditional advice about not negotiating with extortionists still holds — but the reputational and legal damage from a published biometric dataset is in a different category than leaked email addresses. Companies collecting sensitive surveillance data need to treat it with proportionally higher security investment.
