HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
The Madison Square Garden Company
bd_bac334239d2900d9 · schema v1 · pii pii-v1
Full breach record for The Madison Square Garden Company →The Madison Square Garden Company disclosed a payment card breach affecting magnetic stripe data swiped at MSG venues between November 2015 and October 2016. External unauthorized access led to the installation of malware capturing card numbers, names, and expiration dates. MSG engaged security firms, fixed the vulnerability, and notified customers.
California clockDiscovered Oct 24, 2016 → Notified Nov 22, 201629d ✓ CA 60-day OK29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_95f9788c687e3e9fOregon State AGfiled 2016-11-22Candidate
- bd_f8a97af7137b8007Washington State AGfiled 2016-11-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65042
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2016
- Raw hash
- eb15172d3437d74e0ca211a3bbe11f0261a4d7601e02853b44a2f9da5a27e159
Reporting entity
- Name
- The Madison Square Garden Companynorm: the madison square garden
Victim entity
- Name
- The Madison Square Garden Companynorm: the madison square garden
Incident
- Discovered
- Oct 24, 2016
- Materiality determined
- —
- Notification sent
- Nov 22, 2016
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- working with law enforcement regarding this matter
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 24, 2016→ Notified: Nov 22, 201629d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.