Madison Square Garden Entertainment Corp.
ent_815f632c6eae8378
Disclosures
17
SEC 10-K Item 1C · State AG · Leak Site · 14 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
38,393
nationwide · State AG IN
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Madison Square Garden Entertainment Corp.
- Normalized
- madison square garden entertainment— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001952073
- Domain
- msgentertainment.com
Disclosure history (17)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-08-12
Madison Square Garden Entertainment Corp. disclosed a historical cybersecurity incident in November 2016 involving a payment card issue at New York and Chicago venues. The incident was addressed with security firms and enhanced security measures were implemented. The filing describes general cybersecurity risk management policies and governance but does not disclose details of any current or recent material breach.
- Indiana State AGas victim2026-02-26
Madison Square Garden Entertainment Corp reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-31 and was reported on 2026-02-26. 60 Indiana residents were affected. 38,393 individuals affected in total.
- Vermont State AGas reporting2026-02-26
The Madison Square Garden Family of Companies notified consumers of a data breach involving Oracle eBusiness Suite. An unauthorized party exploited a vulnerability in the application, hosted by a vendor, to access workforce and financial data including names and Social Security numbers starting in August 2025. The incident was discovered in November 2025. Affected individuals were offered one year of credit monitoring.
- New Hampshire State AGas victim2026-02-26
Madison Square Garden Entertainment Corp. notified the New Hampshire Attorney General of a data breach involving 12 state residents. An unauthorized party exploited a previously undisclosed vulnerability in the Oracle eBusiness Suite (hosted by a third-party vendor) in August 2025, gaining access to names and Social Security numbers. The breach was discovered in late November 2025. Notifications were mailed on February 26, 2026, offering one year of credit monitoring.
- Massachusetts State AGas victim2026-02-26
Madison Square Garden Entertainment Corp notified Massachusetts residents of a data security incident involving their name and Social Security number. The notice, dated February 23, 2026, offers two years of complimentary credit monitoring via Cyberscout. The specific cause, dates of occurrence, or number of affected individuals are not disclosed in the letter.
- Nebraska State AGas victim2026-02-26
Madison Square Garden Entertainment Corp. notified Nebraska AG that unauthorized access to its Oracle eBusiness Suite occurred in August 2025, exploiting a previously undisclosed vulnerability. The breach exposed names and Social Security numbers of 11 Nebraska residents. Notifications were mailed starting February 26, 2026, offering one year of credit monitoring.
- California State AGas reporting2026-02-26
The Madison Square Garden Family of Companies notified California residents of a data breach involving their Oracle eBusiness Suite. An unauthorized person exploited a previously undisclosed vulnerability in the application, hosted by a third-party vendor, to access data in August 2025. The investigation determined in late November 2025 that files containing names and Social Security numbers were accessed. The company engaged forensic investigators, notified law enforcement, and is offering one year of complimentary credit monitoring services.
- Maine State AGas victim2026-02-26
Madison Square Garden Entertainment Corp. reported a data breach affecting 11 Maine residents. An unauthorized person exploited a previously undisclosed condition (zero-day) in the Oracle eBusiness Suite, hosted by a vendor, to access data in August 2025. The investigation determined access occurred between August 10 and October 21, 2025, and was discovered in late November 2025. Names and Social Security numbers were exposed. Notifications were sent on February 26, 2026, offering one year of credit monitoring.
- Illinois State AGas victim2026-02-01
MADISON SQUARE GARDEN ENTERTAINMENT CORP. filed a data-breach notice with the Illinois Attorney General in February 2026 (case 26-02-1011). The register records the breach as discovered on December 16, 2025. Personal information types reported: ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2025-11-21
MSG.com is a website owned by The Madison Square Garden Company, a sports and entertainment company based in the United States. The site features content pertaining to the company's various properties, including the New York Knicks, the New York Rangers, and Madison Square Gardens. It provides news, updates, event schedules, ticket purchasing options, and more.
- Massachusetts State AGas reporting2025-08-20
MSG Services Group, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-08-20. 2 Massachusetts residents were affected.
- South Carolina State AGas victim2016-11-23
The Madison Square Garden Company notified customers of a payment card incident affecting magnetic stripe data swiped at MSG venues between Nov 9, 2015 and Oct 24, 2016. External unauthorized access led to installation of a program capturing card data. Affected data included card numbers, names, expiration dates, and verification codes. MSG engaged security firms, fixed the issue, and notified law enforcement.
- Montana State AGas victim2016-11-22
The Madison Square Garden Company notified customers of a payment card incident affecting magnetic stripe data swiped at MSG venues between Nov 9, 2015 and Oct 24, 2016. External unauthorized access led to the installation of a program capturing card data. MSG engaged security firms, stopped the access, and notified law enforcement.
- Oregon State AGas victim2016-11-22
The Madison Square Garden Company reported a data breach to the Oregon Attorney General. The breach was reported on 2016-11-22. The breach occurred during 11/9/2015. The breach was discovered on 10/27/2016. 1 individuals were affected. Notice was sent on 11/22/2016.
- New Hampshire State AGas victim2016-11-22
The Madison Square Garden Company (MSG) notified the NH Attorney General of a payment card security incident. Unauthorized access to MSG's payment processing systems occurred between Nov 9, 2015 and Oct 24, 2016. Magnetic stripe data (card numbers, names, expiration dates, verification codes) from in-person swipes at MSG venues may have been affected. MSG engaged security firms, reset passwords, implemented 2FA, and notified law enforcement. No specific count of affected individuals was disclosed.
- California State AGas victim2016-11-22
The Madison Square Garden Company (MSG) notified customers of a payment card data breach affecting transactions at MSG venues in New York and Chicago between November 9, 2015, and October 24, 2016. External unauthorized access to MSG's payment processing system allowed the installation of a program that captured magnetic stripe data, including card numbers, names, expiration dates, and verification codes. MSG discovered the incident in late October 2016 after banks identified suspicious transaction patterns. The company engaged security firms, contained the breach, and implemented enhanced security measures. No specific count of affected individuals was disclosed.
- Washington State AGas victim2016-11-22
The Madison Square Garden Company (MSG) reported a cyberattack affecting payment card data (magnetic stripe data) at its venues from Nov 2015 to Oct 2016. Unauthorized access allowed installation of malware capturing card data. MSG engaged forensic firms, reset passwords, implemented MFA, and notified law enforcement. No specific count of affected individuals was disclosed due to lack of customer contact info.
Supply-chain cascadesreviewed and confirmed
- Madison Square Garden Entertainment Corp.’s filing is one of at least 7 in the ORACLE CORPORATION supply-chain incident (2025).