CSIDB logo
Incident

Madison Square Garden

Incident posture

Attack window
Aug 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 02:32

Linked entities

Victim
Madison Square Garden
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Nov 2025
Disclosed
Mar 2026
Resolved
Pending

Summary

Madison Square Garden confirmed a data breach resulting from a cybercrime campaign that exploited zero‑day vulnerabilities in Oracle’s E‑Business Suite to steal over 210 gigabytes of archive files. The attackers, linked to the Cl0p ransomware group, leaked the data after the venue declined to pay a ransom. Although the arena initially did not respond to inquiries, it later acknowledged the incident and began notifying affected individuals. The compromised Oracle EBS instance was hosted by a third‑party vendor, whose investigation showed that personal information such as names and Social Security numbers had been taken. While the total number of impacted people remains unclear, the venue reported to the Maine Attorney General’s Office that eleven residents of that state were affected.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The incident began as part of a broader cybercrime campaign that targeted customers of Oracle’s E‑Business Suite (EBS) solution. The Cl0p ransomware and extortion group exploited zero‑day vulnerabilities to infiltrate the EBS environments of more than 100 organizations. In November 2025 the hackers publicly identified Madison Square Garden (MSG) as one of the victims of this campaign. They claimed to have exfiltrated over 210 gigabytes of archive files from MSG’s systems. The data leak followed shortly after the alleged theft, indicating that MSG had refused to meet the ransom demand. At the time MSG did not respond to repeated requests for comment from media outlets. The breach remained unconfirmed by the venue for several months while the stolen data circulated underground.

In early 2026 MSG Entertainment issued a confirmation that it had suffered a data breach linked to the Oracle EBS incident. The company began notifying individuals whose personal information had been compromised as part of the breach response. MSG Entertainment stated that the affected Oracle EBS instance was hosted and managed by a third‑party vendor. The vendor’s investigation determined that the unauthorized access and data exfiltration occurred in August 2025. The compromised data included personal identifiers such as names and Social Security Numbers. While the total number of affected individuals has not been disclosed, MSG Entertainment informed the Maine Attorney General’s Office that 11 residents of Maine were among those impacted. The notification process is ongoing as MSG works to fulfill its obligations under applicable data breach disclosure laws.

Sources

Sources available to members: 1 source.

CSIDB