ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Madison Square Garden faces class action lawsuit over breach of 26m customer records

A class action lawsuit has been filed against New York-based sporting venue Madison Square Garden after the ShinyHunters group leaked over 26 million customer records following the expiry of its ransom payment deadline.

 

On June 16, the ShinyHunters extortion group leaked as many as 26 million customer records that it allegedly stole from the systems of Madison Square Garden. The group said it infiltrated the sporting venue’s computer systems, exfiltrated stored customer information, and gave the company until June 15 to pay a ransom.

 

“It’s very simple. When you pay us, your data is deleted, and you move on with your life. When you don’t pay us,
you get posted here, among other things,” the extortion group posted on its leak site, sharing a compressed 42GB customer records database that could be downloaded by anyone.

 

The stolen records included customers’ names and personally identifiable information along with their facial recognition and biometric details which Madison Square Garden collected to build lengthy and accurate profiles of people visiting its venue.

 

On the same day, a Madison Square Garden customer named Carlos Avalos filed a class action lawsuit against the company in the U.S. District Court for the Southern District of New York, alleging that the company violated multiple data privacy laws which led to the massive data breach.

 

Avalos alleged that considering ShinyHunters had given the company a deadline to pay a ransom, the company knew about the data breach beforehand but failed to inform affected customers about the data security incident. He also alleged that despite facing multiple data privacy lawsuits, the company continued to collect massive amounts of biometric information about customers without implementing adequate safeguards. 

 

“Unfortunately, Defendant has a tempestuous history with respect to data privacy,” Avalos said in his complaint. “Defendant is infamous for collecting biometric facial recognition data from each consumer which enters into the Arena. Despite a slew of lawsuits regarding this conduct, as well as consternation from privacy advocates and legislators in New York, the Arena – at the direction of its owner James Dolan – continues to collect biometric information from each visitor.”

 

“The reason for this is to use biometric data and combine it with other characteristic information and social media posting to create threat assessment profiles on each entrant into the Arena, which, upon information and belief, may have been compromised in this Data Breach,” he added.

 

Avalos also alleged that Madison Square Garden failed to adequately protect its customers’ personally identifiable information from cyber attacks and failed to apply adequate security to the hardware used to store its customers’ personal and biometric information.

 

The class action lawsuit claims that Madison Square Garden introduced a facial recognition system in 2018 to carry out mass surveillance on millions of visitors and to ban certain visitors who raised a red flag. The company allegedly used surveillance cameras and security personnel disguised as police officers to spy on local protestors and place an entry ban on about 1,200 lawyers who were involved in privacy lawsuits against it.

 

It further alleged that Madison Square Garden commissioned a third -party company called XtractOne to run its surveillance systems and process a wide array of customer data to assign threat profiles to visitors, including those whose social media posts were deemed unfavourable to the company’s interests. XtractOne processed and tagged profiles of even children to assign threat markers.

 

The class action lawsuit further stated that Madison Square Garden has failed to notify its customers about the data security incident, the nature and scope of the incident, or what actions it is taking to prevent a similar incident from occurring in the future.  

 

“Defendants have offered zero remediation for the Data Breach whatsoever – so all of the costs of taking reventative action, such as paying for credit monitoring, are costs that are borne by the victims as opposed to the billion-dollar corporate Defendant.

 

“Finally, Defendant has yet to disclose the full nature of the breach and whether the information that Defendant still has in its control is now in fact secure. This leaves victims with zero reassurance that Defendant has taken steps to protect their PII from being exposed yet again due to Defendant insufficient cybersecurity apparatus,” the lawsuit added.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543