The Madison Square Garden Company
ent_2a155dc51d262553da85aca7
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Madison Square Garden Company
- Normalized
- the madison square garden— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🍁Vermont State AGas victim2026-02-26
The Madison Square Garden Family of Companies notified consumers of a data breach involving Oracle eBusiness Suite. An unauthorized party exploited a vulnerability in the application, hosted by a vendor, to access workforce and financial data including names and Social Security numbers starting in August 2025. The incident was discovered in November 2025. Affected individuals were offered one year of credit monitoring.
- 🦫Oregon State AGas victim2016-11-22
The Madison Square Garden Company reported a data breach to the Oregon Attorney General. The breach was reported on 2016-11-22. The breach occurred during 11/9/2015. The breach was discovered on 10/27/2016. 1 individuals were affected. Notice was sent on 11/22/2016.
- 🐻California State AGas victim2016-11-22
The Madison Square Garden Company disclosed a payment card breach affecting magnetic stripe data swiped at MSG venues between November 2015 and October 2016. External unauthorized access led to the installation of malware capturing card numbers, names, and expiration dates. MSG engaged security firms, fixed the vulnerability, and notified customers.
- 🌲Washington State AGas victim2016-11-22
The Madison Square Garden Company, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2016-10-27 and filed notice on 2016-11-22. 26 days elapsed between awareness and notification. 353 days to identify the breach. 0 days to contain the breach.