Madison Square Garden
Incident posture
Linked entities
- Victim
- Madison Square Garden
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Madison Square Garden confirmed a data breach resulting from a cybercrime campaign that exploited zero‑day vulnerabilities in Oracle’s E‑Business Suite to steal over 210 gigabytes of archive files. The attackers, linked to the Cl0p ransomware group, leaked the data after the venue declined to pay a ransom. Although the arena initially did not respond to inquiries, it later acknowledged the incident and began notifying affected individuals. The compromised Oracle EBS instance was hosted by a third‑party vendor, whose investigation showed that personal information such as names and Social Security numbers had been taken. While the total number of impacted people remains unclear, the venue reported to the Maine Attorney General’s Office that eleven residents of that state were affected.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The incident began as part of a broader cybercrime campaign that targeted customers of Oracle’s E‑Business Suite (EBS) solution. The Cl0p ransomware and extortion group exploited zero‑day vulnerabilities to infiltrate the EBS environments of more than 100 organizations. In November 2025 the hackers publicly identified Madison Square Garden (MSG) as one of the victims of this campaign. They claimed to have exfiltrated over 210 gigabytes of archive files from MSG’s systems. The data leak followed shortly after the alleged theft, indicating that MSG had refused to meet the ransom demand. At the time MSG did not respond to repeated requests for comment from media outlets. The breach remained unconfirmed by the venue for several months while the stolen data circulated underground.
In early 2026 MSG Entertainment issued a confirmation that it had suffered a data breach linked to the Oracle EBS incident. The company began notifying individuals whose personal information had been compromised as part of the breach response. MSG Entertainment stated that the affected Oracle EBS instance was hosted and managed by a third‑party vendor. The vendor’s investigation determined that the unauthorized access and data exfiltration occurred in August 2025. The compromised data included personal identifiers such as names and Social Security Numbers. While the total number of affected individuals has not been disclosed, MSG Entertainment informed the Maine Attorney General’s Office that 11 residents of Maine were among those impacted. The notification process is ongoing as MSG works to fulfill its obligations under applicable data breach disclosure laws.
Sources
Sources available to members: 1 source.