More than 26 million customer and corporate records, including raw biometric surveillance logs, were posted publicly on June 16. The archive, about 45 gigabytes in size, appeared after a claimed breach on June 5 and a missed June 15 ransom deadline, with the hacking collective ShinyHunters offering victims a pay-to-delete option on its leak site. Reporters who reviewed the dump found ticketing records, customer account details and internal profiling tied to Madison Square Garden Entertainment's long running use of facial recognition, along with direct contact information for talent. A federal class action filed the same day alleges negligent collection and retention of sensitive identifiers, while security analysts say the publication reflects a shift toward data exfiltration and public exposure.
Labels such as 'low risk' and 'high risk' appeared in leaked files, a federal complaint filed June 16 said. The filing cites entries that classify celebrities and attendees and ties the published material to biometric tracking logs, background checks, internal risk assessments and dossiers on visitors and performers. The plaintiff says his biometric data was captured at a 2025 concert and is seeking damages.
What the dump contains
Reporters who reviewed samples of the archive found a mix of routine and sensitive material. A sample reviewed by independent reporters contained fields labelled "address," "claim to fame," "cost of talent," plus direct contact information for talent and representatives. 404 Media reported files that tied Knicks-related personalities to customer records and corporate correspondence, and said ticketing operations records and account details for both the Knicks and the Rangers were present in the published archive.
More alarming to privacy advocates is the presence of raw biometric outputs and public complaints stored alongside them. The published materials included fan emails in which attendees complained of being misidentified by MSG’s cameras, and the complaint specifically notes the inclusion of biometric surveillance logs that track individuals across venues. The addition of those surveillance records expands the potential scope of harm beyond the usual risks tied to exposed payment data or email addresses, because biometric identifiers are long lived and difficult to change.
Timeline and the extortion method
ShinyHunters posted a short negotiation timeline before publishing the files, telling Madison Square Garden Entertainment to contact the group before June 15 or face publication. Sources reported MSG did not pay, and the files became publicly available on June 16. The group’s message on its leak site framed the choice as pay to delete or see the material posted. Security analysts quoted in coverage framed the episode as part of a broader shift in criminal tactics, away from encryption ransomware aimed at locking systems for payment, and toward pure data exfiltration paired with public shaming to force victims to pay.
The materials the hackers published, and the way they were released, will be central to both the class action and any regulatory or law enforcement inquiries. The complaint draws attention to how aggressively the company gathered and retained sensitive identifiers, describing those practices as negligent.
The filing gives concrete examples that feed the legal claims, such as the categorisation of public figures by perceived risk and the storage of detailed dossiers.
Madison Square Garden Entertainment, which owns the New York Knicks and other venue properties, now faces litigation and scrutiny rooted in a pattern of prior incidents. Reporting notes at least two earlier major compromises: a 2015 to 2016 point-of-sale malware incident that exposed payment data, and a 2025 breach blamed on the Cl0p ransomware group that exploited an Oracle E Business Suite vulnerability and exposed names and Social Security numbers for tens of thousands of people. This latest publication is the first in that series to attach biometric surveillance records to the pool of exposed material.
Beyond the immediate legal stakes, the leak makes people wonder about how venue operators gather and hold personal data tied to security and commercial operations. The complaint says MSG retained not just summaries but raw biometric outputs and visitor tracking logs. That combination, the filing argues, turns routine operational data into a persistent privacy liability for millions of people who visited MSG-controlled venues.
404 Media and other outlets that reviewed the files described internal correspondence alongside customer records, suggesting the breach touched multiple systems. The presence of emails from fans raising concerns about facial recognition indicates the company recorded both the biometric outputs and public pushback in the same systems. Those details matter to the class action claim that MSG failed to secure data it aggressively gathered.
Lawyers for the plaintiff framed the complaint around statutory and compensatory relief, while the filing itself provides the early evidentiary basis for claims that sensitive biometric identifiers were improperly protected. Federal litigation began with the filing on June 16. Related investigations and potential regulatory or law enforcement actions were reported, though no hearings or rulings were specified in the materials reviewed.
For Madison Square Garden Entertainment, the immediate headache will be defending against the class action and answering questions from investigators and corporate partners. For the millions whose records appear in the published archive, the risk is longer term. Biometric identifiers do not expire the way passwords do, and the complaint shows that the exposure of those identifiers heightens the potential for enduring privacy and identity harms.
Related Articles
- 6 Amazon gadgets on early Prime Day deals, including Fire TV
- Token costs surge as firms scramble to control bills
- iOS 27 boosts older iPhone speed, up to 80% faster
The filing on June 16 launches federal litigation that will test whether MSG's biometric collection and retention practices meet legal standards. The next milestones are initial court motions and any regulatory or law enforcement inquiries that follow.
This article was created with AI assistance.