Madison Square Garden (MSG) Entertainment Corp. has confirmed a data breach stemming from a cybersecurity incident that occurred in August 2025. The company began notifying affected individuals in late February 2026 after concluding an investigation into the months-old attack.
Key Details of the Breach
- The Cause: Hackers exploited a zero-day vulnerability in the Oracle E-Business Suite (EBS) managed by a third-party vendor.
- The Timeline: While the unauthorized access took place in August 2025, MSG Entertainment reportedly learned of the vulnerability around December 16, 2025.
- The Attacker: The Cl0p ransomware and extortion group claimed responsibility, leaking stolen data after the company refused to pay a ransom demand.
- Compromised Information: The breach involved sensitive personal data, including Full Names, Addresses, and Social Security Numbers (SSNs).
Ongoing Actions
- Notifications: MSG Entertainment is currently mailing notice letters to impacted customers.
- Legal Scrutiny: Law firms like Edelson Lechtzin LLP have launched investigations into potential class-action lawsuits on behalf of victims.
- Monitoring: If you believe you are affected, experts suggest monitoring your credit reports and account statements for suspicious activity immediately.