The lawyers MSG banned with facial recognition are now the plaintiffs suing over it - 251
July 4, 2026
Madison Square Garden spent years building one of the most extensive facial recognition surveillance systems of any entertainment venue in the country — controversially using it to identify and bar lawyers from firms that had sued the company, alongside routine visitor screening. Now that same system has become the source of its own undoing: ShinyHunters leaked 45 gigabytes of stolen data, including biometric records on 26 million visitors, after MSG's parent company missed a ransom deadline, and the surveillance apparatus built to track guests is now the subject of federal litigation over exactly the practice that made it possible.
The scope of what leaked goes well beyond biometric templates. Alongside facial recognition tracking logs, the stolen data includes internal threat assessments, background check records, and detailed attendee dossiers, some dating back to 2018 — years of accumulated profiling on individual visitors, not a single snapshot. The dump also exposed information on New York Knicks players, coaches, and talent, including addresses, contact details, and a field labeled "cost of talent," alongside customer emails that included complaints from fans who had previously raised concerns about being misidentified by MSG's own facial recognition cameras — meaning the very people who flagged the system's accuracy problems are now also victims of its security failure. Privacy advocates have pointed to this combination as the clearest illustration yet of what unchecked biometric collection actually produces once it's compromised: not an anonymized dataset, but detailed, persistent profiles built on individuals without clear consent, now sitting fully exposed.

The legal response arrived quickly and specifically. A federal class-action suit, Avalo v. MSG Entertainment, was filed on June 16 in a New York court, with plaintiff Carlos Avalo alleging his biometric data was captured during a 2025 concert visit without proper disclosure, seeking at least $5 million in initial damages under biometric privacy statute violations. The timing compounds an existing trust problem for the company: this marks MSG's second major breach in under a year, and the company has yet to publicly confirm the full scope of the exposure or respond to the litigation, an unusually thin public response given the sensitivity of what was actually stolen.

ShinyHunters, the group claiming responsibility, is no stranger to high-profile targets — Kodak and Instructure both feature in its prior activity — and the group says its initial access came not through any technical exploit against MSG's surveillance infrastructure, but through social engineering a single low-level employee. That detail is the incident's most uncomfortable throughline: an organization sophisticated enough to deploy biometric screening across its venues, precise enough to use facial recognition against specific law firms as a business tactic, was ultimately breached through the same human vulnerability that undoes far less advanced security programs entirely. The technology worked exactly as designed for years — it simply was never protected as carefully as it was deployed.