← All posts

A Phone Call, a Face Scan, and 26 Million Reasons to Rethink AI Surveillance

On June 5, someone at Madison Square Garden Entertainment answered a phone call. It was a voice phishing attack — old-school social engineering, nothing fancy. A low-level employee handed over credentials that gave the ShinyHunters cybercrime group access to Microsoft Entra, the identity platform MSG uses to manage its network. From there, the hackers moved methodically through MSG's systems and walked out with 45 gigabytes of data.

Ten days later, when MSG missed the ransom deadline, ShinyHunters published everything.

What made this breach different from the usual dump of emails and credit card numbers was what was in that data: facial recognition surveillance records from MSG's AI-powered entry system, internal threat-assessment dossiers on celebrities and public figures, and what the hackers claim are records from 26 million visitors. The verified numbers are bad enough on their own — 9.8 million email addresses, approximately 5 million street addresses and full names, and biometric tracking logs that classified people by internal risk ratings with no documented criteria.

By June 18, at least five proposed class action lawsuits had been filed against MSG Entertainment in federal court.

The Real Problem Isn't the Hack — It's What They Were Collecting

In my experience, the first question boards ask after a breach is "how did they get in?" That's the wrong question. The right question — the one that determines your legal exposure — is "why did we have that data in the first place?"

MSG had been using facial recognition technology at its venues for years. They used it to identify banned individuals, including attorneys whose firms had active litigation against the company. They compiled dossiers on activists and critics. They assigned internal risk ratings to celebrities walking through the door. And they stored all of it.

None of this was secret. MSG's facial recognition practices had drawn public scrutiny as early as 2022. What the breach did was force the question every board should have been asking: if this data gets out, what happens?

Now we know. Class action lawsuits. Regulatory scrutiny. Reputational damage that no incident response plan can contain.

The Three Questions, Applied

In Cyber Risk Is Business Risk, I lay out the Three Questions framework that every executive should be asking about their organization's cyber posture. The MSG breach is a case study in what happens when those questions go unasked.

What data are we collecting, and do we actually need it? MSG was hoarding biometric data on millions of visitors — facial scans, movement patterns, risk classifications. The business case for banning a handful of litigating attorneys does not justify building a surveillance database of 26 million people. Your AI governance policy should start with a data minimization question, not a capabilities question.

Who has access, and how do we know? A single vishing call to a low-level employee opened the entire kingdom. Microsoft Entra managed identity across MSG's environment, and once ShinyHunters had those credentials, they had everything. If your identity platform is a single point of failure, your board needs to know that — and they need to know what happens when it fails.

What's our exposure if this goes wrong? Here's where it gets expensive. New York doesn't have a biometric privacy statute with a private right of action, so the class action suits are proceeding on common-law negligence. But if MSG had been running facial recognition at its Chicago Theatre, they'd be facing claims under Illinois' Biometric Information Privacy Act — $1,000 per negligent violation, $5,000 per intentional one. Multiply that by millions of scanned faces and the math gets existential fast.

The Timing Is Not Coincidental

The MSG breach landed three weeks after the SEC's Regulation S-P compliance deadline for smaller entities on June 3, 2026. Those amendments require covered institutions to maintain written incident response programs and notify affected individuals when sensitive customer information is compromised. Larger entities have been under these requirements since December 2025.

The regulatory direction is clear. Boards now carry formal accountability for cybersecurity oversight. The NACD's 2026 Director's Handbook on Cyber-Risk spells it out: 78 percent of large-cap companies now house cybersecurity oversight in their audit committees. Courts are applying the Caremark standard to cybersecurity governance, meaning directors face personal liability if they fail to implement reporting systems for cyber risk.

Meeting minutes are evidence. Delegation without verification is a disclosure obligation. If your board's cybersecurity briefings consist of a CISO presenting a green dashboard once a quarter, you are exposed.

What to Ask Your CISO This Week

If you're a board member or C-suite executive reading this, here's what should be on your agenda before the next board meeting:

On AI and data collection: "Do we use facial recognition, biometric scanning, or any AI-powered surveillance system? If so, what data are we retaining, for how long, and under what legal authority? Has outside counsel reviewed our retention policy against the biometric privacy laws in every jurisdiction where we operate?"

On identity and access: "What would happen if an attacker compromised our identity management platform through social engineering? How many systems does that unlock? When was the last time we tested that scenario?"

On incident readiness: "Do we have a written incident response program that meets Regulation S-P requirements? Has it been tested in the last twelve months? Who owns notification to affected individuals, and what's the timeline?"

These are not technical questions. They are governance questions. And after the MSG breach, they are questions your plaintiffs' attorneys will ask in discovery if you can't show you asked them first.

The Bigger Picture

The MSG breach is a preview of what happens when organizations deploy powerful AI surveillance tools without matching governance structures. Facial recognition is not going away. Biometric data collection is accelerating. The organizations that survive the next wave of breaches will be the ones that asked the hard questions about data minimization, access control, and regulatory compliance before the phone rang.

The breach started with a phone call. The liability started years earlier, when someone decided to scan every face walking through the door and nobody at the board level asked why.