GoFirm
Back to Blog
Case Studies·3 min read

The Knicks Won a Championship. Madison Square Garden Reportedly Lost 26 Million Customer Records

By GoFirm

On 5 June 2026, the day the New York Knicks clinched their first NBA championship in 53 years, the organisation that owns them was quietly being emptied of its data. A vishing call reached a low level Madison Square Garden Sports Corp employee, and within minutes the caller, posing as internal IT support, had what they needed: access to Microsoft Entra, the identity platform MSG uses to manage authentication and network access across its ticketing, venue, and corporate systems.

No malware was involved and no vulnerability was exploited. The attacker convinced one employee that the call was routine, walked them through a process that looked like standard credential verification, and came away holding a valid Entra identity. From there the attacker pivoted directly into MSG's customer and talent databases, governed by the same identity provider that controls years of ticketing records, venue entry logs, and internal HR files.

By 12 June, ShinyHunters had listed Madison Square Garden Sports Corp and its affiliated entities on its dark web leak site, claiming more than 26 million customer records and roughly 45GB of internal corporate data. MSG was given until 15 June to pay. The deadline passed unmet, and within days the group published the trove in full.

Independent analysis of the leaked files found 9.8 million email addresses, close to 5 million street addresses, full names, phone numbers, and 9,500 dates of birth. A file named Talent listed former Knicks players and coaches, MSG executives' family members, and visiting celebrities, some carrying an internal threat assessment rating: the actor Ben Stiller was marked low risk, the rapper A Boogie Wit da Hoodie was marked high risk. The most sensitive material was the facial recognition surveillance data MSG collects at its venues to screen visitors, including individuals the company has barred for reasons unrelated to any security threat. Three class action lawsuits followed within a week, one naming MSG's facial recognition programme directly and noting this was not the company's first breach, pointing to prior incidents in 2015 and 2025.

The defences that failed here were not weak by conventional standards. MSG ran an enterprise identity platform, applied access controls across its systems, and operated one of the most extensive physical biometric surveillance networks of any venue operator in the country. None of it mattered at the one moment that counted: when a single employee, on a phone call, was asked to hand over the credential that opened everything. No firewall, no facial recognition camera, no encryption standard sits at that decision point. The employee believed the caller. That was sufficient.

A credential grant to an identity provider like Microsoft Entra is an execution event. Before any employee can approve, reset, or extend access at that level, GoFirm sends a real time confirmation request to the named authority for that action, on their own registered device, over a channel the caller on the phone cannot touch. The Entra access ShinyHunters obtained would have required biometric confirmation from the actual employee or their designated authority before it took effect, not after a call sounded convincing enough.

The same control point would have sat in front of the subsequent export from MSG's customer and talent databases. A bulk export of that scale is itself an execution event, and it does not proceed without a second, independent confirmation from the person authorised to approve it. A vishing call, however convincing, cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. TechRadar (Sead Fadilpasic), "Charter Communications confirms data breach - ShinyHunters blamed after threat to leak user info online", 27 May 2026. https://www.techradar.com/pro/security/charter-communications-confirms-data-breach-shinyhunters-blamed-after-threat-to-leak-user-info-online

2. GBlock, "One Vishing Call Cost Charter 40 Million Customer Records", 28 May 2026. https://www.gblock.app/articles/charter-ters-blamed-a40m-salesforce-vishing-breach-may-2026

3. eSecurity Planet, "ShinyHunters Alleges 42M Records Stolen from Charter Communications". https://www.esecurityplanet.com/threats/ters-blamed-aalleges-42m-records-stolen-from-charter-communications/

Share this article