Menu
Browse

Cyber Incident Victim: Madison Square Garden

Date:

Aug 2025

Location:

United States of America

Summary

Madison Square Garden confirmed a data breach after attackers exploited a zero‑day vulnerability in Oracle’s E‑Business Suite, stealing over 210 GB of data that included names and Social Security numbers. The breach, discovered months after the initial attack, led to notifications to affected individuals, with at least eleven residents of one state identified among those impacted.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

In August 2025, hackers exploited zero‑day vulnerabilities in Oracle’s E‑Business Suite to infiltrate the system hosted by a third‑party vendor for Madison Square Garden, exfiltrating more than 210 gigabytes of archive files. The intrusion was part of a broader campaign by the Cl0p ransomware and extortion group that targeted over 100 organizations using the same software. In November 2025, the attackers publicly identified Madison Square Garden as one of their victims and leaked the stolen data, a move the article notes indicated the organization had refused to pay a ransom. During this period, Madison Square Garden did not respond to repeated requests for comment about the incident.

Cyber Incident Image

Months later, on March 2 2026, Madison Square Garden Entertainment confirmed that it had suffered a data breach and began notifying individuals whose personal information had been compromised. The notification disclosed that the affected Oracle EBS instance was hosted and managed by a third‑party vendor, whose investigation determined that the data theft occurred in August 2025. The compromised personal information includes names and Social Security numbers, though the total number of affected individuals remains unspecified. The organization also reported to the Maine Attorney General’s Office that eleven residents of Maine were among those impacted.

As part of its response, Madison Square Garden Entertainment is working with the third‑party vendor to continue the investigation and to mitigate further risk, while fulfilling its obligation to inform affected parties. The breach adds to the list of organizations affected by the Oracle EBS hacking campaign, which has also impacted entities such as the University of Phoenix, LKQ, and Korean Air. No further details about the scope of the breach or additional remedial steps have been disclosed in the available source material.

Sources
Sources available to members
1 source