Attorney Advertising  ·  The Alvarez Law Firm  ·  Coral Gables, FL

LAWSUIT
Loop
See If You Qualify
Data Breach Lawsuits Filed

MSG Data Breach May Have Exposed Your Face Scan, Social Security Number, and More

A hacker group stole and published 45 gigabytes of private data from Madison Square Garden Entertainment. Up to 26 million people who attended events at MSG venues may have had their most sensitive personal information — including their face scans — exposed.

By Lawsuit Loop Staff · Published June 23, 2026 · 5 min read · Lawsuits Active
Stock image — not an actual client or case

⚠️ Heads Up — If you attended a Knicks game, Rangers game, concert, or any other event at an MSG venue, your personal data — including your face scan — may have been exposed. Use the form below to share your situation and find out if you have options.

Madison Square Garden Entertainment has been using facial recognition technology to scan the faces of everyone who walks through the doors of its venues — including the famous arena in New York City, Radio City Music Hall, the Beacon Theatre, and others. That data was stored in its systems. And in June 2026, a criminal hacking group got to it.

The hackers, a group known as ShinyHunters, published 45 gigabytes of internal MSG files after the company missed a ransom deadline on June 15, 2026. Within days, five separate class action complaints were filed in federal court in New York by people who say their private information was taken and exposed without their consent.

What Information Was Exposed?

According to the lawsuits and published reports, the breach exposed an unusually sensitive combination of personal data:

  • Biometric facial recognition data — a digital scan of your face, mapped and stored as a unique identifier
  • Social Security numbers
  • Credit scores and financial information
  • Background check records
  • Names, addresses, and other personal details

As many as 26 million people are believed to be affected. That estimate comes from the data the hackers published online after MSG failed to pay the ransom.

Your face scan cannot be changed the way a password can. Once that data is out, it is out permanently.

Why Is Biometric Data Different?

Most data breaches expose information that is bad but fixable. If your credit card number is stolen, you can get a new card. If your email password is taken, you can reset it.

Your face cannot be reset. Biometric data — including facial recognition scans — is a permanent part of who you are. Once it is out in the world, it can be used in ways that are very hard to defend against, including creating fake identities or bypassing security systems that rely on facial recognition.

This is why laws in several states specifically protect biometric data, and why courts take these breaches seriously.

What Did MSG Do — and What Went Wrong?

MSG has been using facial recognition at its venues for years, sparking controversy long before this breach. The company used the technology not only for general security but to identify and turn away attorneys involved in lawsuits against MSG — a practice that drew significant attention and criticism.

The hackers who carried out this breach, ShinyHunters, are a well-known criminal group responsible for multiple high-profile data theft incidents. According to the lawsuits, MSG’s security systems failed to protect the enormous amount of personal data it had collected from visitors, including the biometric information gathered at its doors.

This was also not MSG’s first breach. In early 2026, a separate hacker group had already exploited a different vulnerability in MSG’s systems, exposing data on more than 130,000 people.

Who Is Filing These Lawsuits?

Five class action complaints were filed in federal court in New York between June 16 and June 18, 2026. The first was filed by a man who attended a concert at MSG in September 2025 and says his personal information was collected and then exposed without adequate protection. Four additional complaints followed over the next two days.

The lawsuits accuse MSG of collecting visitors’ data without properly protecting it, failing to put adequate safeguards in place, and not doing enough to prevent the kind of breach that occurred.

Do You Have a Claim?

You may have options if you attended any event at an MSG venue and your personal information may have been exposed. You do not need to have received a notice letter from MSG, and you do not need to have suffered a specific financial loss yet to speak with an attorney about your situation.

  • You attended a Knicks, Rangers, or other event at Madison Square Garden in New York City
  • You attended a show at Radio City Music Hall, the Beacon Theatre, or another MSG-owned venue
  • You have concerns about your biometric data, Social Security number, or other personal information

This situation is still developing. New information about who was affected and what data was taken continues to come out. The sooner you speak with an attorney, the more options you may have. Filing deadlines apply to data breach matters just like any other legal situation.

Common Questions

According to the lawsuits and news reports, the breach exposed biometric facial recognition data, Social Security numbers, credit scores, background check records, and other personal information. The hackers published 45 gigabytes of files after MSG missed a ransom deadline.
Potentially. MSG has used facial recognition technology to scan visitors at its venues. If you attended any event at Madison Square Garden, Radio City Music Hall, the Beacon Theatre, or another MSG venue, your biometric data may have been collected and may be among the data exposed.
No. You do not need to wait for an official notification letter. If you attended an MSG venue and believe your data may have been exposed, you can speak with an attorney now about your options.
Unlike a password or credit card number, you cannot change your face. A biometric facial scan is a permanent digital fingerprint tied to your identity. If that data is stolen, the exposure cannot be undone. That permanence is one reason courts and state laws treat biometric data breaches with particular seriousness.
Yes. Every legal matter has a deadline, and waiting too long can permanently end your ability to seek help. The lawsuits in this case were just filed in June 2026. If you believe your information was exposed, do not wait to find out if you have options.
MSG Data Breach

Did You Attend an MSG Event?

If you attended a Knicks game, Rangers game, concert, or any other event at an MSG venue, your biometric and personal data may have been exposed in the breach. This short form is free and takes about two minutes.

Free to check
No cost, no obligation to proceed.
Your information is private
What you share is confidential.
Deadlines apply
Don’t wait — your rights can expire.
Free Case Review

Find out if you may have options.

Fill out this short form. A member of our team will follow up if your situation may qualify.

Free Case Review · Confidential 2 min · No obligation
What Happens Next

If your information suggests you may qualify, someone from our team will reach out within 7 days. If you do not hear back within that time, please contact another law firm — every legal matter has a filing deadline, and waiting can cost you your right to recover.

Related Stories

See If You Qualify See If You Qualify — Free