A proposed class action lawsuit landed in New York federal court this week against Madison Square Garden Entertainment, alleging the company left the personal data of up to 26 million arena visitors exposed to a cybercrime group, and then said nothing about it.
The suit, filed one day after the hacking collective ShinyHunters publicly claimed to have breached MSG's internal systems, names plaintiff Carlos Avalo and accuses the entertainment giant of collecting vast troves of biometric facial recognition data and Social Security numbers from visitors without adequately protecting any of it.
As of June 19, MSG Entertainment had not publicly responded to either the alleged breach or the lawsuit. The company declined to comment when asked by The U.S. Sun. That silence speaks volumes for the millions of concertgoers, sports fans, and event attendees who handed over their information just to walk through the doors of one of America's most famous arenas.
The complaint, reviewed by Front Office Sports, paints a picture of an organization that kept collecting sensitive personal data even after repeated warnings that it could not keep that data safe. The suit alleges MSG Entertainment has a "tempestuous history with respect to data privacy", and the record bears that out. The arena was already hit by a cyber attack in 2016, when hackers acquired credit card details from customers.
Yet the company kept expanding its data collection. The lawsuit states that "despite a slew of lawsuits regarding this conduct, as well as consternation from privacy advocates and legislators in New York, the Arena, at the direction of its owner James Dolan, continues to collect biometric information from each visitor."
That is a direct accusation leveled at Dolan, the executive chairman and CEO of MSG Entertainment. The suit names him personally as the figure directing the arena's biometric data collection practices.
The complaint goes further, alleging the company "continued to collect, retain, and otherwise use the personal information of consumers to create threat assessments and for other purposes despite showing it was clearly incapable of handling this sensitive data."
"Threat assessments." That phrase deserves attention. It suggests MSG was not merely scanning tickets or verifying identities. It was building profiles on its own customers, and, if the hackers' claims prove accurate, leaving those profiles wide open.
The cybercrime group ShinyHunters announced on Monday that it had penetrated MSG Entertainment's internal systems. The group claimed access to biometric facial recognition data and Social Security numbers belonging to as many as 26 million people who visited Madison Square Garden. The outlet 404Media first reported the group's claim.
By Tuesday, the class action was filed. Plaintiff Carlos Avalo says he attended an MSG concert last year and that his personal information was collected during that visit. He claims to be "gravely concerned" by the leak and believes his data is among those accessed.
Whether ShinyHunters has published any of the allegedly stolen data, or merely claims to possess it, remains unclear. No law enforcement agency has publicly confirmed an investigation into the breach. The specific method of intrusion has not been disclosed. These are serious gaps, and MSG's refusal to comment only widens them.
New York has become a recurring site of institutional data failures. Just recently, a three-month data breach at a New York City hospital system exposed the records of 1.8 million patients, prompting a Senate chairman to demand answers. The MSG breach, if confirmed at the scale alleged, would dwarf that incident by an order of magnitude.
The 2016 cyber attack on MSG should have been a wake-up call. Credit card details were stolen. Lawsuits followed. Privacy advocates raised alarms. Legislators in Albany voiced concern. And yet, according to the complaint now before a federal judge, the arena's leadership doubled down on data collection, adding biometric surveillance to the mix.
Madison Square Garden has been at the center of public attention for other reasons this year. The arena drew enormous crowds and national interest during the Knicks' NBA Finals run, a stretch that also saw fifty-six people taken into custody and ten NYPD officers injured in post-game disorder near the Garden.
That playoff run brought celebrities, politicians, and everyday fans flooding through MSG's gates. If the arena was scanning faces and collecting biometric data from every visitor during that period, the potential scope of exposure grows considerably.
The Games themselves attracted considerable cultural attention, with moments ranging from Whoopi Goldberg defending Trump's appearance at a Finals game to viral confrontations in the stands. Every one of those attendees may now be wondering what MSG did with their data, and who else has it.
The lawsuit does not yet specify the damages or relief sought, and no case number has been publicly reported. The law firm representing Avalo has not been identified in available reporting. But the core allegation is straightforward: MSG Entertainment collected extraordinarily sensitive personal information, failed to protect it, and has yet to own up to any of it.
MSG Entertainment and Madison Square Garden Sports, which owns the Knicks and Rangers, are separate entities, though both are controlled by James Dolan. Only MSG Entertainment is named as a defendant. That corporate structure may matter in court, but it will matter less to the fans who bought tickets, passed through facial recognition scanners, and trusted that their biometric data would not end up in the hands of a criminal syndicate.
Biometric data is not a credit card number. You can cancel a card. You cannot change your face. If ShinyHunters' claims hold up, the people affected are not just dealing with a financial inconvenience. They are dealing with a permanent compromise of information that is, by definition, irreplaceable.
The arena that has hosted some of the most memorable moments in American sports and entertainment now faces a question far less glamorous: did it treat its own customers' most sensitive information as an afterthought?
MSG's continued silence is not a legal strategy anyone should admire. The company has had no shortage of opportunities to address controversy at the Garden in recent months. On a matter this consequential, biometric data, Social Security numbers, 26 million potential victims, saying nothing is a choice. And it is the wrong one.
Corporate America has spent years collecting more and more personal data from consumers, often with minimal transparency and even less accountability. Facial recognition at entertainment venues is one of the more aggressive frontiers of that trend. When companies adopt surveillance-grade technology to manage their own paying customers, they assume an obligation to protect what they collect. That is not a progressive talking point. It is common sense.
The lawsuit against MSG Entertainment is, for now, a set of allegations. ShinyHunters' claims have not been independently verified. The federal court process will determine whether the facts support the plaintiff's case. But the underlying pattern, collect everything, protect nothing, say nothing when it goes wrong, is one Americans have seen too many times from too many institutions.
Twenty-six million people walked into Madison Square Garden to watch a game, see a concert, or enjoy a show. They did not sign up to have their faces catalogued and their Social Security numbers handed to hackers. If MSG's leadership cannot explain how this happened and what it is doing about it, a federal judge will eventually make them.
When an institution treats your data like its property and your security like someone else's problem, accountability does not arrive on its own. Sometimes it arrives in a courtroom.