Madison Square Garden Faces Class Actions Over a Facial-Recognition Data Breach (2026)

Independently fact-checkedBy Recording Law Editorial Team10 min read

Independently fact-checked against primary sources (last audited June 24, 2026). · 4 primary sources cited on this page. How we verify our legal content

Madison Square Garden Faces Class Actions Over a Facial-Recognition Data Breach (2026)

Frequently Asked Questions

Was MSG facial recognition data leaked?

Plaintiffs and breach reporting allege that the hacking group ShinyHunters published roughly 45 GB of MSG internal data including facial-recognition entry records. Those claims are unproven allegations; as of June 24, 2026, no court has confirmed the scope of the breach, and MSG has not validated the hackers figures.

What is the MSG data breach lawsuit?

The lead suit is Avalo v. Madison Square Garden Entertainment Corp., No. 1:26-cv-05095, filed June 16, 2026 in the U.S. District Court for the Southern District of New York. A concertgoer alleges his biometric and facial data were scanned at entry and exposed in the breach, and pleads negligence and negligence per se.

Can you sue for a facial-recognition data breach in New York?

In New York, plaintiffs generally bring common-law negligence claims rather than a biometric-statute claim, because the state has no biometric-privacy statute with a private right of action. Whether such a suit succeeds depends on standing, duty, breach, and injury, which the court decides.

Does New York have a biometric privacy law like Illinois BIPA?

No. New York has no statewide biometric-privacy statute giving individuals a private right of action comparable to the Illinois Biometric Information Privacy Act (740 ILCS 14). That difference is why the MSG suits plead negligence instead of a biometric-statute claim.

What is the New York SHIELD Act and does it apply here?

The SHIELD Act (N.Y. Gen. Bus. Law 899-aa and 899-bb) requires businesses to maintain reasonable data-security safeguards and to notify New York residents of breaches. It is enforced by the state attorney general, not by private plaintiffs, though plaintiffs may cite its reasonable-safeguards duty in a negligence theory.

How much money does the MSG complaint seek?

The Avalo complaint seeks at least $5 million in damages on behalf of a proposed class, plus restitution and a court order requiring MSG to overhaul its data-security and data-retention practices. The amount is a pleading; no damages have been awarded.

How many lawsuits have been filed against MSG over the breach?

Reporting indicates that as many as five proposed class actions had been filed in the Southern District of New York by June 18, 2026, all arising from the same alleged breach and resting on similar negligence theories. The number may change as the docket develops.

Has a court found MSG liable?

No. As of June 24, 2026, these are filed complaints with unproven allegations. No court has ruled on the merits, found MSG liable, or confirmed the breach figures asserted by the hackers and plaintiffs.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. N.Y. Gen. Bus. Law 899-aa (data-breach notification)(nysenate.gov).gov
  2. N.Y. Gen. Bus. Law 899-bb (reasonable data-security safeguards)(nysenate.gov).gov
  3. New York Attorney General, SHIELD Act overview(ag.ny.gov).gov
  4. Illinois Biometric Information Privacy Act, 740 ILCS 14(ilga.gov).gov
  5. Biometric Update reporting on the MSG breach lawsuits (corroboration)(biometricupdate.com)
Share: