LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Madison Square Garden Sports Data Breach (2026)

HIGH severityConfirmedHow we verify

Madison Square Garden Sports Data Breach (2026): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 5, 2026

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Madison Square Garden Sports Data Breach (2026)

Reported June 5, 2026. Approximately 9.8M people affected.

HIGH
Severity
9.8M
People affected
5
Data types exposed
June 5, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Madison Square Garden Sports disclosed a data breach on June 5, 2026, affecting 9.8 million people whose customer service records, email addresses, names, phone numbers, and physical addresses were exposed. If you have an account or received services from the organization, review the details and consider changing passwords or monitoring your accounts for suspicious activity.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
9.8M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In June 2026, Madison Square Garden Sports was the target of an extortion campaign attributed to the group ShinyHunters. The group later published material it claimed to have taken from the company, affecting 9.8 million people and containing nearly 10 million unique email addresses along with other personal details. For individuals whose records are involved, the practical consequence is that verified names, addresses, and contact information have been placed in circulation. This can increase exposure to unsolicited contact or attempts to leverage the data in further schemes.

Breaking down the breach

The incident was reported on June 5, 2026. Available information states that ShinyHunters conducted a “pay or leak” extortion campaign against Madison Square Garden Sports and subsequently published the data it alleged to possess. The published material is described as covering almost 10 million unique email addresses belonging to both staff and customers, together with additional personal, employment, and customer relationship information. No further details on the initial access method, the precise volume of files, or the timeline of the intrusion have been disclosed in public reporting.

The group behind it: shinyhunters

ShinyHunters is a threat actor group that has conducted multiple data extortion operations in recent years. Its typical pattern involves obtaining large datasets from corporate environments, contacting the affected organization with a ransom demand, and releasing the material on public leak sites when payment is not made. In statements tied to this case, the group claimed responsibility for the Madison Square Garden Sports incident and made the data available after the extortion phase concluded. Attribution rests on the group’s own listings rather than independent forensic confirmation in the available record.

Madison Square Garden Sports and its sector

Madison Square Garden Sports is a sports and entertainment company that manages professional teams and venue operations. Companies in this sector maintain records for ticketing, memberships, event access, and customer service interactions. These records commonly include contact information and service history that span large customer bases and staff directories. When such datasets are published, the scale of affected individuals tends to be high because the organizations serve millions of fans and employees over time.

The information in question

The data types named in connection with the incident are customer service records, email addresses, names, phone numbers, and physical addresses. Reporting also refers to extensive personal, employment, and customer relationship information. The exact contents of any published files have not been independently verified beyond the descriptions provided by the group. Organizations of this type routinely hold additional categories such as payment details or access credentials, but those elements are not confirmed in the current record.

The real-world impact

People whose contact details appear in the material may receive a measurable increase in phishing attempts or fraudulent calls that reference known personal information. Employment-related details, where present, can be used to craft more convincing impersonation attempts. For the organization, the publication adds a documented case to the growing list of entertainment and sports entities that have had customer and staff records released following extortion demands. No specific financial or operational losses beyond the data exposure itself have been stated in the available facts.

What to do if you're exposed

Individuals concerned about possible exposure should review recent account activity on services tied to the listed email addresses and enable multi-factor authentication where available. Monitoring incoming communications for unusual requests that reference personal details can help identify misuse early. A free exposure scan of an email address against known breach datasets can be performed through established public lookup services.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMadison Square Garden Sports security record
64/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Madison Square Garden Sports’s full breach history →

More recent breaches

Ralph Lauren Data Breach (2026)June 11, 20267-Eleven Data Breach (2026)April 8, 2026Sysco Data Breach (2026)June 15, 2026American Tower Data Breach (2026)June 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Madison Square Garden Sports Data Breach (2026) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram