← Blog

MSG Sports Breach: HIBP Indexes ~9.8M Emails

Share on X

Have I Been Pwned added Madison Square Garden Sports after ShinyHunters ran a June 2026 “pay or leak” campaign and published alleged data. The HIBP load covers about 9,796,738 accounts—nearly 10 million unique email addresses spanning staff and customers, plus personal, employment, and customer-relationship fields.

This is not the same incident as the earlier MSG Entertainment Oracle E-Business Suite / Clop case (~131,000 records). Different corporate entity, different actor, different scale.

What happened

404 Media and later lawsuit coverage described Knicks- and MSG-related files appearing online after the extortion listing. HIBP’s breach page cites the ShinyHunters campaign and lists compromised data classes including emails, names, phone numbers, physical addresses, and customer-service records.

At the time HIBP indexed the dump, it was treated as an independently verified corpus load—not a tidy company press release confirming every field.

What data was exposed

  • Email addresses (~9.8M unique in HIBP)
  • Names, phone numbers, and physical addresses
  • Customer-service and employment/CRM-style information (per HIBP)

Who is at risk

Anyone who used an email with MSG Sports properties, Knicks ticketing/CRM flows, or related customer service—and employees whose work mail appears in the set. Expect long-tail phishing that name-drops the Knicks championship cycle or “ticket refund” themes.

Action items

  1. Check your address on Have I Been Pwned.
  2. Change passwords anywhere you reused MSG-related credentials; turn on MFA.
  3. Treat unexpected Knicks/MSG ticket or “account review” messages as hostile until verified in official apps.

Canonical record

https://breachhistory.com/madison-square-garden-sports/madison-square-garden-sports-shinyhunters2026 — sources: HIBP, 404 Media.