← All posts

One Phone Call, 26 Million Records: What the Madison Square Garden Breach Means for Every Board

On June 5, a member of the ShinyHunters cybercrime group picked up a phone and called a low-level employee at Madison Square Garden Entertainment. Using a technique called vishing — voice phishing — the caller impersonated a trusted contact and talked the employee into handing over credentials to Microsoft Entra, the identity platform that controls network access across MSG's operations. Within hours, the attackers had what they came for.

Eleven days later, after MSG failed to meet a ransom deadline, ShinyHunters published 45 gigabytes of stolen data. The dump contained far more than ticket-buyer emails. It included facial recognition surveillance records collected since 2018, internal threat assessment profiles built on venue attendees, VIP dossiers, and what the group claims are records tied to 26 million customers and corporate contacts.

Five federal class-action lawsuits have already been filed in the Southern District of New York. One of them, Avalos v. MSG Entertainment Corp., seeks at least $5 million in initial damages and could eventually include anyone who attended a MSG venue since the facial recognition program launched.

Here is the detail that should keep every board member awake: this is MSG's second major breach in under a year. In February, the company disclosed that the Cl0p ransomware group had exploited a zero-day vulnerability in an Oracle eBusiness Suite application used for payroll and HR, exposing Social Security numbers and personal data of approximately 131,000 employees and contractors. That intrusion occurred between August and October 2025 and was not discovered until December.

Two breaches. Two different attack vectors. Two different threat actors. The common thread is not a specific technical failure — it is a governance failure.

The Three Questions Every Board Should Be Asking

In Cyber Risk Is Business Risk, I outline a framework built on three questions that boards need to ask consistently: What are our most critical assets? Who is responsible for protecting them? How do we know our defenses are working?

Apply those questions to MSG and the gaps become obvious.

What are our most critical assets? MSG was collecting biometric facial recognition data on every person who walked through its doors. It was building internal dossiers on attendees it deemed potential threats. That is an extraordinary volume of sensitive personal data — and an extraordinary liability. The board's first obligation was to understand that this data existed, what its exposure meant, and whether the organization had the security posture to protect it. The class-action lawsuits now allege the company failed on all three counts.

Who is responsible for protecting them? The June breach started with a single phone call to a low-level employee. Social engineering remains the most effective initial access technique in cybersecurity, and it does not require a sophisticated technical exploit. It requires an attacker who understands human behavior and an organization that has not invested adequately in security awareness at every level. When the entry point is a vishing call, the question for the board is not "why didn't our firewall stop this?" It is "does our security culture extend to every employee who can answer a phone?"

How do we know our defenses are working? The February breach went undetected for four months. The attackers operated inside MSG's Oracle eBusiness Suite between August and October 2025, and the intrusion was not discovered until December. A board that had been asking this third question — and demanding evidence, not assurances — would have known whether its detection capabilities were adequate long before a threat actor proved they were not.

Compliance Is Not Security

A Harvard Business Review article published in April identified three reasons boards continue to fall short on cybersecurity. One of them cuts directly to the heart of what happened at MSG: boards mistake regulatory compliance for security. Authors Jeffrey Proudfoot and Stuart Madnick argue that boards should view cybersecurity "less as a compliance-driven regulatory issue and more as a competitive, operational resilience issue, where market incentives and organizational accountability drive stronger security outcomes than government-imposed rules."

MSG was presumably compliant with applicable regulations when it began collecting facial recognition data in 2018. Compliance did not prevent two breaches, 45 gigabytes of leaked surveillance data, and five federal lawsuits. Compliance is the floor. Security is the ceiling. Boards that confuse the two will keep learning this lesson the expensive way.

What to Ask Your CISO This Week

The MSG breach is not an isolated incident. ShinyHunters has been on a sustained campaign in 2026, exploiting an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach more than 100 organizations, with approximately 68 percent of them in higher education. The Aflac breach disclosed this month affected 22.7 million people. The attack surface is expanding, and the attackers are not slowing down.

If you sit on a board or in a C-suite, here are five questions worth raising before your next committee meeting:

  1. Do we know what sensitive data we collect, and have we stress-tested whether we need all of it? MSG's facial recognition program created a massive liability. Data you do not collect cannot be breached.
  2. When was our last social engineering exercise, and what were the results? Vishing, phishing, and pretexting remain the most common initial access vectors. If your security program focuses on technical controls and ignores the human layer, you have a gap.
  3. What is our mean time to detect an intrusion? MSG's February breach went undetected for four months. Ask for a number, not a narrative.
  4. Have we been breached before, and what changed afterward? A second breach within a year suggests the remediation from the first one was insufficient. Boards should be tracking whether post-incident recommendations were actually implemented.
  5. Does our cyber insurance cover the regulatory and litigation exposure we actually face? Five class-action lawsuits and the potential inclusion of every MSG attendee since 2018 represent a scale of liability that many policies would not fully cover.

The MSG breach is a case study in what happens when cyber risk is treated as someone else's problem. It is not an IT problem. It is not a compliance problem. It is a business risk that starts in the boardroom — and when boards fail to own it, the consequences land on millions of people who trusted the organization with their personal data.