← All Articles

Carlos Avalos v. Madison Square Garden Entertainment Corporation Alleges MSG Failed to Secure PII of 26M Consumers

Carlos Avalos, representing a class of affected individuals, has initiated litigation against Madison Square Garden Entertainment Corporation (MSG) in the United States District Court (Case No. 1:26-cv-05095-JAV). The complaint, filed on June 16, 2026, claims MSG's alleged negligence led to a significant data breach compromising the personal information of millions of consumers, with damages believed to exceed $5 million. Avalos asserts that MSG failed to implement adequate security measures to safeguard sensitive data, including biometric information, which was subsequently accessed and leaked by the hacker group ShinyHunters.

Alleged Data Breach Mechanism

The complaint asserts that Madison Square Garden Entertainment Corporation (MSG) failed to protect the personally identifiable information (PII) of its patrons, leading to a significant data breach orchestrated by the cybercriminal group ShinyHunters on June 16, 2026. These claims form the basis of the class action complaint, alleging that MSG's negligence and inadequate security protocols directly contributed to the data breach and its ensuing consequences. The case reflects ongoing concerns about corporate responsibility in safeguarding consumer data in an era of increasing cyber threats.

Monetary Figures in Dispute

The complaint in Carlos Avalos v. Madison Square Garden Entertainment Corporation articulates a substantial amount in controversy estimated at $5,000,000, exclusive of interests and costs. This figure reflects the significant damages sought by the plaintiffs on behalf of themselves and similarly situated individuals whose personally identifiable information (PII) was exposed in the alleged data breach.

A notable point raised in the complaint involves MSG's $6 million investment in XtractOne. The investment was intended for security improvements, specifically to enhance biometric and facial recognition capabilities. Despite this significant financial outlay, the complaint alleges that these security measures were inadequate, ultimately failing to prevent the data breach that compromised the personal information of millions of Arena visitors.

In terms of market impact, the complaint alleges a strong probability that batches of information stolen in the breach have been or will be dumped on the black market, citing dark web pricing under which stolen PII can sell for $40-$200 per piece and credit/debit card numbers for $5-$110 each (Compl. ¶¶87-88). These transactions underscore the financial incentive for cybercriminals and the alleged financial injury to the plaintiffs, who contend that MSG's security failures exposed them to increased risks of fraud and identity theft.

Parties and Roles

The plaintiff in this case is Carlos Avalos, who is bringing the action on behalf of himself and a proposed class of similarly situated individuals. This class is represented in a lawsuit against Madison Square Garden Entertainment Corporation (MSG), which is the defendant. MSG is a Nevada corporation with its principal place of business located in New York, NY. The complaint alleges that MSG failed to safeguard sensitive personal information (PII) of consumers and thereby violated federal and state laws.

Non-parties referenced in the complaint include ShinyHunters, a cybercriminal organization allegedly responsible for breaching MSG's networks and leaking consumer data. Additionally, XtractOne is mentioned as the recipient of a $6 million investment from MSG intended for security improvements that, according to the complaint, failed to prevent the breach. The Federal Trade Commission (FTC) and the United States Government Accountability Office (GAO) are also referred to within the complaint, pointing to prior reports and guidelines that were allegedly not adhered to by MSG.

Negligence and Negligence Per Se Claims

The complaint filed by Carlos Avalos accuses Madison Square Garden Entertainment Corporation (MSG) of negligence and negligence per se for its alleged failure to properly safeguard personal identifiable information (PII) of over 26 million consumers. The negligence per se claim further asserts that MSG violated Section 5 of the Federal Trade Commission Act, which prohibits unfair practices that affect commerce. According to the complaint, MSG’s failure to utilize adequate security measures and its delay in informing data breach victims constitute unfair practices as outlined by the FTC Act.

Distinctive Allegations

The complaint asserts that Madison Square Garden Entertainment Corporation (MSG) implemented a facial recognition system in 2018, which was used to collect biometric data from individuals attending events at its venues. This practice has allegedly raised significant privacy concerns, with the plaintiffs particularly highlighting the collection of data from various attendees without their informed consent. The use of such technology purportedly extends to assigning threat scores to individuals, a feature that has come under scrutiny when scores were assigned to children and NYPD recruits, potentially affecting their privacy and reputations.

Moreover, the complaint alleges MSG relied on disguised security personnel who posed as police officers, adding another layer of concern regarding the company's security practices and potential overreach (Compl. ¶19).

Past Security Incidents and Recommendations Ignored

Prior to the breached event instigated by ShinyHunters, the complaint highlights a history of security lapses at MSG, including a significant point-of-sale attack between 2015 and 2016 that compromised payment cards. These incidents emphasize a pattern of inadequate security practices. The plaintiffs contend that MSG failed to heed recommendations from federal and state laws as well as guidelines set by the FTC, which emphasize thorough monitoring as a critical component for preventing data breaches (Compl. ¶112).

Moreover, the 2007 GAO report on data breaches, which should have alerted MSG to evolving threats in data security, was published long before the company faced breaches like the one caused by ShinyHunters, suggesting prior knowledge and yet insufficient action (Compl. ¶77).

Inadequate System Monitoring and Resultant Risks

The plaintiffs allege that MSG's failure to adequately monitor its systems directly contributed to the delayed discovery of the data breach. The breach reportedly became evident only after the ShinyHunters initiated their attack, highlighting inadequate vigilance and system monitoring on the part of MSG (Compl. ¶34). The complaint suggests that these failures not only facilitated the breach but also exposed PII to serious risks of fraud, identity theft, and unauthorized use, underscoring the hazardous consequences of insufficient data security strategies.

Relief Sought and Current Procedural Posture

The complaint in Carlos Avalos, et al. v. Madison Square Garden Entertainment Corporation requests the certification of a class action, setting the stage for a collective legal remedy for all individuals similarly affected by the alleged data breach. In addition, they seek equitable and injunctive relief aimed at safeguarding any remaining sensitive information from future breaches.

To support their case, the plaintiffs also call for the award of attorneys’ fees, along with the reimbursement of legal costs and expenses incurred throughout the litigation. They further request pre- and post-judgment interest on any awarded amounts to account for the time value of money between the occurrence of the harm and the eventual resolution of the case.

The plaintiffs have expressed their preference for a jury trial to resolve the dispute. The class action is structured under the provisions of the Federal Rules of Civil Procedure, including FRCP 23(b)(2), 23(b)(3), and 23(c)(4). This procedural posture positions the case to proceed once MSG files its response to the complaint.

The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.

David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.

From the Complaint Public Court Record

UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF NEW YORK x CARLOS AVALOS, on behalf of himself and all others similarly situated, Plaintiff, v. MADISON SQUARE GARDEN ENTERTAINMENT CORPORATION, Defendant. : : : : : : : : : : : : x Case No. _________________ CLASS ACTION COMPLAINT DEMAND FOR JURY TRIAL

1 CLASS ACTION COMPLAINT Plaintiff CARLOS AVALOS (“Plaintiff”), on behalf of himself and all others similarly situated, brings this Class Action Complaint against Defendant MADISON SQUARE GARDEN CORPORATION (“MSG” or the “Defendant”), for violations of state and common laws set forth herein in connection with Defendant’s failures to allow for the unlawful breach of personally identifiable and sensitive information during the applicable statutory period and continuing through the present day (“Class Period”). Plaintiff makes the following allegations based upon personal knowledge as to himself, extensive investigative and media reporting, dark web postings from the perpetrators, alerts from various data security infrastructures, as well as upon information and the belief and investigation of his counsel as follows: SUMMARY OF THE CASE 1. This is an Action against Defendant MSG for their recidivist disregard for consumer privacy and MSG’s complete and utter failure to properly secure and safeguard personally identifiable information (“PII”) including but not limited to the information of up to 26 million consumers, including Plaintiff’s and Class members’ personal information (the “Data Breach”). 2. Madison Square Garden, which is owned by the Defendant as well as its famous tenants (the NBA champion New York Knicks and the New York Rangers), is well regarded as one of the world’s most famous sports arenas. The arena is the sole professional sports venue located within Manhattan in New York City – and attracts visitors from around the world (the “Arena”).

2 3. Unfortunate

Questions about this topic: david@newmanbrunk.com

Practice areas