Madison Square Garden Admits Hackers Stole SSNs Months After Initial Cyberattack
Mar 2, 2026 // 20:14 - Niko Dunn


Madison Square Garden (MSG) Entertainment Corp. has confirmed a data breach stemming from a cybersecurity incident that occurred in August 2025. The company began notifying affected individuals in late February 2026 after concluding an investigation into the months-old attack.

Key Details of the Breach

  • The Cause: Hackers exploited a zero-day vulnerability in the Oracle E-Business Suite (EBS) managed by a third-party vendor.
  • The Timeline: While the unauthorized access took place in August 2025, MSG Entertainment reportedly learned of the vulnerability around December 16, 2025.
  • The Attacker: The Cl0p ransomware and extortion group claimed responsibility, leaking stolen data after the company refused to pay a ransom demand.
  • Compromised Information: The breach involved sensitive personal data, including Full Names, Addresses, and Social Security Numbers (SSNs).

Ongoing Actions

  • Notifications: MSG Entertainment is currently mailing notice letters to impacted customers.
  • Legal Scrutiny: Law firms like Edelson Lechtzin LLP have launched investigations into potential class-action lawsuits on behalf of victims.
  • Monitoring: If you believe you are affected, experts suggest monitoring your credit reports and account statements for suspicious activity immediately.

#admits  #after  #cyberattack  #garden  #hackers  #initial  #madison  #months  #news  #square  #ssns  #stole   —   News