Cybersecurity

Madison Square Garden VIP Database Leak Reveals Celebrity Risk Labels

Madison Square Garden (MSG) suffered a significant cybersecurity breach when the hacker collective ShinyHunters exfiltrated a database containing detailed profiles of over 39,000 VIPs, including celebrities and public figures associated with the venue. The exposed files revealed not only personal information but also internal risk designations and sensitive labels such as “LGBTQIA” and “DO NOT HOST,” sparking serious concerns about privacy and surveillance practices within MSG’s security operations.

What Happened

On June 16, 2026, the criminal hacker group ShinyHunters announced a breach of Madison Square Garden’s internal systems. The group accessed two prominent datasets: a “talent” database with roughly 39,539 entries tracking celebrities, business leaders, and political figures, and a much larger Salesforce customer management system database containing over 10.5 million personal records. The leaked talent database included assigned risk scores rating VIPs from “flag” (lowest) to “high risk,” influencing who received complimentary event tickets and scrutiny from MSG security. Many well-known individuals—such as rapper Fat Joe, actors Edie Falco and Adam Pally, and musicians like Pete Rock—were tagged with risk labels or barred entirely from receiving complimentary hosting privileges.

Key Facts

  • The breach exposed a VIP “talent” database of 39,539 entries and a Salesforce customer database with more than 10.5 million entries, including nearly 9.8 million unique emails and over 2.8 million unique phone numbers.
  • Risk scores ranged from “flag” to “high risk,” affecting celebrity access to complimentary tickets and security attention.
  • The “talent” database contained sensitive categorizations including sexual orientation, with 93 entries marked “LGBTQIA.”
  • ShinyHunters claimed to have gained access via “employee vishing” on Microsoft Entra, enabling password resets to penetrate MSG’s network.
  • The FBI described ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion targeting major companies.
  • The leak included personal tax documents of MSG employees and internal notes linking VIP risk to public criticism of team ownership and management practices.
  • The disclosure first surfaced publicly via 404 Media and subsequently amplified by WIRED’s investigation into MSG’s surveillance practices.

What This Means

This breach exposes deeply invasive surveillance measures undertaken by a major entertainment venue, raising questions about privacy norms for high-profile visitors. The systematic categorization of individuals by risk—sometimes based on online criticism or personal attributes like sexual orientation—reflects an aggressive and often opaque security posture that could chill free expression and unfairly restrict access to public events.

For the millions affected by the Salesforce data leak, the exposed contact information and personal identifiers heighten the risk of identity theft, phishing, and other cyberattacks, particularly given ShinyHunters’ history of data extortion. This incident highlights not only the vulnerabilities in corporate data management but also the dangers posed by social engineering tactics like vishing that exploit human weaknesses to bypass technical defenses.

More broadly, the breach signals a need for organizations across industries to scrutinize their data collection and surveillance policies and to enforce stricter controls on access to sensitive personal information, especially when that data carries risk scores or labels that could lead to discrimination or retaliation.

Background

ShinyHunters has been active since 2019, targeting high-profile companies across technology, retail, and finance, often stealing millions of customer records and demanding ransoms. In 2025, several alleged members were arrested in France as part of an international law enforcement effort.

Microsoft and Salesforce had issued warnings about “vishing” attacks on corporate sign-on systems as early as 2025, which coincide with ShinyHunters’ known modus operandi. MSG’s breach appears to be distinct from previous intrusions but situated within this broader campaign of targeted social engineering and data theft.

What Remains Unclear

It is not publicly confirmed whether all affected VIPs and customers have been notified about the data breach. The complete scope of compromised systems and whether additional confidential corporate data beyond the known databases was accessed has not been disclosed. The motivations behind MSG’s use of risk scores and the criteria for labels such as “LGBTQIA” or “DO NOT HOST” also remain ambiguous.

What Comes Next

MSG has yet to publicly comment on the breach or announce specific remediation measures. Industry experts recommend organizations strengthen multi-factor authentication, improve employee security training to resist vishing attacks, and limit privileged access within corporate networks. Meanwhile, law enforcement agencies continue investigations into ShinyHunters and seek to disrupt their future operations.

Sources

This article is based on reporting and publicly available information from the following sources:

Read more Cybersecurity stories on Goka World News.

Ethan Clarke
About the editor

Ethan Clarke

Ethan Clarke Role: Cybersecurity Editor Ethan Clarke covers cybersecurity incidents, data breaches, online threats, ransomware, software vulnerabilities, and digital safety. His reporting focuses on confirmed details, affected systems, official advisories, and practical context without making unsupported accusations.

View all posts by Ethan Clarke