HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoverySupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Madison Square Garden Entertainment Corp.
bd_6b451934dfaa0e99 · schema v1 · pii pii-v1
Full breach record for Madison Square Garden Entertainment Corp. →Madison Square Garden Entertainment Corp. notified the New Hampshire Attorney General of a data breach involving 12 state residents. An unauthorized party exploited a previously undisclosed vulnerability in the Oracle eBusiness Suite (hosted by a third-party vendor) in August 2025, gaining access to names and Social Security numbers. The breach was discovered in late November 2025. Notifications were mailed on February 26, 2026, offering one year of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed12 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/madison-square-garden-entertainment-20260226.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 26, 2026
- Raw hash
- 1fd367b86f64b8a8100c44bb1e81c77accb1c3993c3962b57085f5b597a9670a
Reporting entity
- Name
- Madison Square Garden Entertainment Corp.norm: madison square garden entertainment
- Domain
- msgentertainment.com
Victim entity
- Name
- Madison Square Garden Entertainment Corp.norm: madison square garden entertainment
- Domain
- msgentertainment.com
Incident
- Discovered
- Nov 30, 2025
- Materiality determined
- —
- Notification sent
- Feb 26, 2026
- Affected individuals
- 12
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(88 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.