2026 Madison Square Garden Sports — ShinyHunters pay-or-leak; HIBP ~9.8M emails
Data compromised
Email addresses, names, phones, addresses, customer-service and employment/CRM-style fields (per HIBP)
Technical writeup
In June 2026, Madison Square Garden Sports was listed in a ShinyHunters “pay or leak” extortion campaign; the group later published alleged data covering staff and customers. Have I Been Pwned loaded the corpus with about 9,796,738 breached accounts (HIBP overview also rounds to ~10M unique emails), spanning email addresses plus extensive personal, employment, and customer-relationship fields (HIBP lists customer-service records, names, phones, and physical addresses among compromised data classes). 404 Media and subsequent class-action reporting described Knicks/MSG-related files in the leak set. Distinct from the separate MSG Entertainment Oracle E-Business Suite / Clop incident (~131k) already catalogued. Company confirmation of the ShinyHunters dump was not established at HIBP indexing; HIBP load is the primary attested count.
Root cause
ShinyHunters extortion / alleged data theft and publication (company confirmation pending at HIBP load)