HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Madison Square Garden Family of Companies (Madison Square Garden Sports Corp., Madison Square Garden Entertainment Corp., and Sphere Entertainment Co.)
bd_e7bdd410442df1ae · schema v1 · pii pii-v1
Full breach record for The Madison Square Garden Family of Companies (Madison Square Garden Sports Corp., Madison Square Garden Entertainment Corp., and Sphere Entertainment Co.) →The Madison Square Garden Family of Companies notified California residents of a data breach involving their Oracle eBusiness Suite. An unauthorized person exploited a previously undisclosed vulnerability in the application, hosted by a third-party vendor, to access data in August 2025. The investigation determined in late November 2025 that files containing names and Social Security numbers were accessed. The company engaged forensic investigators, notified law enforcement, and is offering one year of complimentary credit monitoring services.
California clockDiscovered Nov 30, 2025 → Notified Feb 23, 202685d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_66b8b6b5e23d3e10Leak Sitecl0pfiled 2025-11-21(94d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_eaa3e48a101e2936Maine State AGfiled 2026-02-26(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619390
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2026
- Raw hash
- e11edad61b160fc3ebc279107407b7a2f0139ee566eb6a71a0b0ee753fa692ff
Reporting entity
- Name
- The Madison Square Garden Family of Companies (Madison Square Garden Sports Corp., Madison Square Garden Entertainment Corp., and Sphere Entertainment Co.)norm: the madison square garden family of companies madison square garden sports corp madison square garden entertainment corp and sphere entertainment
- Domain
- msg.com
Victim entity
- Name
- The Madison Square Garden Family of Companies (Madison Square Garden Sports Corp., Madison Square Garden Entertainment Corp., and Sphere Entertainment Co.)norm: the madison square garden family of companies madison square garden sports corp madison square garden entertainment corp and sphere entertainment
- Domain
- msg.com
Incident
- Discovered
- Nov 30, 2025
- Materiality determined
- —
- Notification sent
- Feb 23, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- CA 60-day late · 85dLeak >90dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 30, 2025→ Notified: Feb 23, 202685d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Feb 23, 2026→ AG copy submitted: Feb 23, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.