Madison Square Garden Data Breach Confirmed After Hacker Attack
MSG Entertainment Confirms Data Breach Stemming from Oracle EBS Cybercrime Campaign
A prominent entertainment company has confirmed a data breach stemming from a cybercrime campaign targeting customers of Oracle’s E-Business Suite (EBS) solution.
Breach Details
The breach, which was first reported in November 2025, involved the exploitation of zero-day vulnerabilities by the Cl0p ransomware and extortion group.
The hackers gained access to data stored by over 100 organizations using the enterprise management software.
Madison Square Garden (MSG) Identified as a Victim
Madison Square Garden (MSG) was identified as one of the victims of the campaign, and data allegedly stolen from the company was leaked by the cybercriminals shortly after.
MSG initially declined to comment on the incident but has since confirmed that it suffered a data breach and has begun notifying affected individuals.
According to notifications from MSG Entertainment, the compromised Oracle EBS instance was hosted and managed by a third-party vendor.
An investigation by the vendor found that hackers stole data in August 2025.
The stolen data includes personal information, such as names and Social Security numbers.
The total number of affected individuals is unclear, but MSG Entertainment reported that 11 residents of Maine were impacted.
Incident Highlights Risks and Importance of Robust Security Measures
The incident highlights the risks associated with third-party vendors and the importance of robust security measures to protect sensitive data.
The breach also underscores the ongoing threat posed by the Cl0p ransomware and extortion group, which has targeted numerous organizations in recent months.
Related News
In related news, the Cl0p group has been linked to a series of high-profile breaches involving Oracle EBS customers.
The group’s tactics typically involve exploiting zero-day vulnerabilities to gain access to sensitive data, which is then used to extort ransom payments from the affected organizations.
Reminder of the Need for Cybersecurity Prioritization
The MSG breach serves as a reminder of the need for organizations to prioritize cybersecurity and implement robust measures to protect against emerging threats.
This includes regularly updating software and systems, implementing robust access controls, and conducting regular security audits to identify vulnerabilities.
