MSG Entertainment Data Breach Legal Investigation: Social Security Numbers Exposed for Over 131,000 Employees and Contractors

By Logan Lowe
Attorney

February 28, 2026


Woods Lonergan PLLC is a nationally recognized complex commercial and civil litigation firm that represents clients in select data breach class actions nationwide. Our data breach lawyers are currently investigating a significant data breach involving Madison Square Garden Entertainment Corp. (NYSE: MSGE).

Our Data Breach Lawyers have a proven record of holding national corporations, technology vendors, healthcare facilities, and educational institutions accountable when failures in cybersecurity expose the sensitive personal and financial information of individuals, workers, and partners.

MSG Entertainment Corp., the world-renowned entertainment leader headquartered in New York, has reportedly confirmed a security incident involving its Oracle eBusiness Suite that has exposed the sensitive personal data—including Social Security numbers—of approximately 131,070 individuals, including current and former employees, stagehands, and corporate vendors.


If you suspect your data was exposed, Call Our Data Breach Lawyers 24/7 at (332) 378-0376 or email loganlowe@woodslaw.com for a free and confidential consultation.

We take no fees unless you win.


The MSG Entertainment Data Breach: Cutting-Edge Entertainment vs. Legacy Security Failures

On February 23, 2026, official filings with the Maine and California Attorneys General revealed that MSG Entertainment fell victim to a sophisticated cyberattack targeting its back-end operational software.

While MSG is famous for its “state-of-the-art” technology—from the MSG Sphere’s immersive displays to its controversial use of facial recognition—our investigation is examining a data breach which reportedly occurred when unauthorized parties exploited a vulnerability in a vendor-hosted Oracle eBusiness Suite application. 

While the intrusion began in August 2025, MSG reportedly did not discover the breach until December 16, 2025, and waited until late February 2026 to notify victims. This six-month “blind spot” may have left over 131,000 people vulnerable to identity theft without their knowledge.

Who Is Impacted by the MSG Data Breach and What Personal Data Was Stolen?

The “blast radius” of this breach is concentrated among the workforce that keeps MSG’s iconic venues running. Because the Oracle system handles payroll, tax, and HR logistics, the potential victims include:

  • New York Venue Staff: Current and former employees of Madison Square Garden, Radio City Music Hall, and the Beacon Theatre. This includes full-time corporate staff, seasonal event workers, and members of the IATSE and other unions.
  • Sphere (Las Vegas) Workforce: Because the Sphere at the Venetian shares MSG’s centralized HR and payroll “plumbing,” thousands of Nevada-based employees who launched the venue in 2024–2025 are likely part of this class.
  • Independent Contractors & Corporate Vendors: Photographers, security consultants, freelancers, and small business owners who provided services to MSG and had their Tax ID or Social Security numbers stored for payment processing.

The records allegedly exposed in the MSG Entertainment breach include:

  • Full names and physical home addresses
  • Social Security numbers (SSNs)
  • Financial identifiers used for payroll or accounts payable

MSG Entertainment Data Breach FAQs

Who is MSG Entertainment Corp. (NYSE: MSGE)?

MSG Entertainment owns and operates a portfolio of iconic venues, including Madison Square Garden, Radio City Music Hall, the Beacon Theatre, and the Sphere in Las Vegas. They also produce the Radio City Christmas Spectacular.

How do I know if my Social Security number was stolen?

If you worked for or provided contracted services to an MSG venue between 2018 and 2025, you should look for a physical letter in the mail titled “Notice of Data Breach.” You can also contact our firm to help verify if your information was part of the 131,070 records reported to state regulators.

Why is an SSN leak more dangerous than a credit card leak?

A Social Security number is a “static” identifier. Unlike a credit card, which can be canceled and reissued, your SSN is permanent. Hackers use SSNs to open fraudulent bank accounts, file false tax returns, and commit long-term identity theft that can take years to resolve.

Does this breach affect people who just bought tickets?

Current reports indicate the breach targeted internal workforce and financial systems (Oracle) rather than the consumer-facing ticket platforms (like Ticketmaster). However, if you are a Premium Suite holder or have a corporate billing account with MSG, your data may be at risk.

How do I join the MSG Entertainment data breach class action?

If you received a notification letter or are a current/former employee concerned about your SSN, you may be eligible to join a class action lawsuit. Contact our data breach lawyers for a free case evaluation. 

What can an MSG Entertainment data breach lawyer do for me?

Our legal team investigates whether MSG Entertainment failed to implement reasonable security measures and whether it violated New York’s SHIELD Act by failing to provide timely notification. We work to recover damages for the heightened risk of identity theft and the loss of your private information.

About Woods Lonergan PLLC

Woods Lonergan PLLC is a nationally recognized law firm specializing in complex civil litigation, including class action, data privacy, and cybersecurity matters. We have a proven track record of successfully holding corporations accountable and protecting the rights of consumers and workers.

Our firm is currently representing plaintiffs in open litigation for numerous significant data breaches, including cases involving Figure Technology, Powerschool, 23andMe, and Yale New Haven Health.

Contact Our Data Privacy Team

If you suspect your data may be exposed, do not wait for the damage to spread.

Call Our Data Breach Lawyers 24/7 at (332) 378-0376 or email loganlowe@woodslaw.com for a free and confidential consultation.

We take no fees, unless you win.

Media Sources and Investigative Reports:

About the Author
Logan Lowe joined Woods Lonergan PLLC in 2009. Since that time, Logan has worked diligently on the firm’s intellectual property and technology law matters, collaborating with the firm’s litigation group on nearly all intellectual property disputes. Logan’s area of concentration includes developing technology, cybersecurity, cryptocurrency, block-chain technology, and GDPR compliance.
Disclaimer: The information in this article and blog post (“post”) is provided for informational purposes only, and may not reflect the current law(s) in every jurisdiction. No information contained in this post should be construed as legal advice from Woods Lonergan PLLC or the individual author(s), nor is it intended to be a substitute for legal counsel on any subject matter. Nothing herein shall be construed to create an attorney-client relationship with Woods Lonergan PLLC. No reader of this post should act or refrain from acting on the basis of any information included in, or accessible through, this Post without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue from an attorney licensed in the recipient’s jurisdiction. This post is attorney advertising.
Attorney Advertising | Disclaimer | Privacy Policy
Website developed in accordance with Web Content Accessibility Guidelines 2.1.
If you encounter any issues while using this site, please contact us: 212.684.2500