BleepingComputer / Sergiu Gatlan04-16-2026ShinyHunters claimed a Salesforce misconfiguration led to theft of 13.5 million McGraw Hill accounts, exposing PII for potential spear-phishing and extortion threats.
BleepingComputer / Sergiu Gatlan05-26-20267-Eleven disclosed an April 2026 Salesforce-linked data breach after ShinyHunters claimed responsibility and leaked PII affecting about 185,300 people.
BleepingComputer / Sergiu Gatlan06-15-2026The Council of Europe began investigating ShinyHunters claims of an HR and payroll data breach in connection with dark web leak threats.
BleepingComputer / Lawrence Abrams07-25-2026Using breach-leaked email addresses, sextortion scammers sent Bitcoin ransom demands in emails tied to exposures from Amtrak and Betterment starting in April.
Cassius Life / Davonta Herring07-10-2026Madison Square Garden faced privacy concerns after ShinyHunters published leaked documents about an alleged people-tracking database with sensitive identity labels.
TechCrunch05-26-2026ShinyHunters claimed a hack-and-extortion attack on 7-Eleven in April, and Have I Been Pwned flagged 185,000+ affected people with sensitive identity data.
CNET06-24-2026Hackers published a reported MSG database in June, exposing customer records and activist dossiers tied to facial recognition surveillance and leading to class-action lawsuits.
New York Times / Christina Caron06-23-2026ShinyHunters allegedly stole data from Madison Square Garden entities before June 16, and class-action lawsuits were filed in the Southern District of New York.
Pitchfork / Walden Green07-23-2026Madison Square Garden disabled facial recognition and camera monitoring during July 2-3 Swift and Kelce events after an internal client privacy request, while legal disputes continue over a leaked talent database.
The Record / Jonathan Greig05-20-20267-Eleven notified Maine, Vermont, and Massachusetts regulators in connection with an April 8 intrusion that exposed franchisee documents containing Social Security numbers.
Cybernews06-15-2026Hackers claim ShinyHunters breached Council of Europe systems, exposing HR and payroll data with personal, financial, and medical records, as the organization has not confirmed.
Endtimeheadlines06-26-2026ShinyHunters reportedly leaked facial recognition and biometric visitor records tied to Madison Square Garden Entertainment in mid-June 2026, leading to a federal class-action filing.
CNET / Tyler Graham06-24-2026Madison Square Garden Entertainment faced privacy allegations in 2026 after a reported data leak exposed activist dossiers and biometric or facial recognition data.
BiometricUpdate.com06-22-2026Madison Square Garden Entertainment faced a federal class action after ShinyHunters claimed to steal and publish biometric and other sensitive data linked to venue facial recognition.
Thought Catalog / Nadia Santiago07-17-2026WIRED reported on July 9 that ShinyHunters exfiltrated an MSG Entertainment talent database with LGBTQIA labels, leading MSG Entertainment to file a defamation lawsuit around July 16.
Mediaite07-10-2026WIRED reported that Madison Square Garden maintained a celebrity database with risk scores and biometric-linked monitoring in New York City, with entries updated through early June.
USA Today07-09-2026Wired reported Madison Square Garden maintained an identity-labeling talent database later leaked by ShinyHunters, followed by class-action lawsuits.
Washington Times07-09-2026ShinyHunters used vishing to access Madison Square Garden systems and leaked a talent database with identity labels and alleged Dolan-criticism risk scores, prompting federal class-action lawsuits.
CNET / Tyler Graham06-24-2026Hackers reportedly published a 45GB cache from Madison Square Garden Entertainment in June, exposing activist dossiers and biometric-linked customer records amid class-action litigation.
CNET / Tyler Graham06-24-2026Madison Square Garden Entertainment faced lawsuits after a June hack reportedly leaked biometric and personal data about customers and activists in New York City.
Tech Times06-21-2026ShinyHunters leaked 297 gigabytes of Council of Europe employee data after a June 16 ransom deadline, citing an Oracle PeopleSoft zero-day exploited before user warnings.
ClassAction.org / Tracy Bagdonas06-17-2026A proposed class action filed after an April 2026 cyberattack alleges 7-Eleven failed to encrypt or redact PII stolen by ShinyHunters.
BleepingComputer / Lawrence Abrams04-13-2026ShinyHunters published an alleged Rockstar Games data leak in 2020s, claiming access via stolen authentication tokens from an Anodot incident impacting Snowflake-linked analytics and support data.
Insurance Business / Matthew Sellers06-28-2026ShinyHunters published 3.1TB of claimed NAIC breach data in late June 2026 after NAIC confirmed an Oracle PeopleSoft intrusion and Google Mandiant confirmed attribution.
CybersecurityNews / Guru Baran04-25-2026ADT confirmed a data breach in an SEC filing on April 24, 2026 after a ShinyHunters claim of more than 10 million customer records.
HITC / Ishika Dadhwal06-18-2026Madison Square Garden Entertainment is sued in New York federal court in a proposed class action over an alleged breach exposing facial-recognition and sensitive consumer data.
Heavy / Jonathan Vankin07-10-2026ShinyHunters leaked Madison Square Garden Entertainment files in 2024, exposing a celebrity risk scoring database and other personal data used for venue screening.
Yahoo07-09-2026ShinyHunters released stolen Madison Square Garden records in June after a ransom threat, exposing an attendee database tied to sensitive identity attributes.
Front Office Sports06-17-2026Carlos Avalo filed a proposed class action in New York federal court alleging Madison Square Garden Entertainment suffered a breach exposing biometric and identity data claimed by ShinyHunters in 2025.
Techtimes / Kyle Belmonte05-24-2026On April 8, 2026, 7-Eleven reported a franchise application systems breach that exposed Social Security and driver's license data for some franchisees, with notifications sent May 1 and regulator filings in Maine, Vermont, and Massachusetts mid-May.
C-Store Dive05-20-20267-Eleven disclosed a spring intrusion discovered April 8, and Massachusetts, Maine, and Vermont filings reported exposure of franchisee names, addresses, and some SSNs and driver’s license data.
All About Cookies / Thomas Kent05-30-2026ShinyHunters published stolen 7-Eleven franchise applicant records on May 24 after a breach discovered April 8 exposed SSNs and driver license details for more than 185,000 people.
Gadgetreview / Nikshep Myle06-16-2026ShinyHunters published a near-45 GB data dump from MSG Sports on a dark-web blog after a June 15, 2026 ransom deadline passed without payment.
GovInfoSecurity06-30-2026Nissan and NAIC confirmed ShinyHunters-linked cyber extortion attacks using a PeopleSoft PeopleTools zero-day, with potential employee data exposure across the U.S., Canada, Mexico, and Brazil.
Endtimeheadlines06-26-2026ShinyHunters allegedly leaked about 45GB of facial recognition and biometric data from Madison Square Garden Entertainment after a missed ransom deadline in mid-June 2026.
BankInfoSecurity / Mathew J. Schwartz06-30-2026ShinyHunters ransomware operators used a PeopleSoft zero-day to extort multiple organizations, including Nissan and NAIC, with breach notifications filed in California.
Databreachtoday06-19-2026ShinyHunters threatened to publish alleged 8.8TB of One Medical patient data on June 22 after unauthorized access to third-party archived health records in June.
Security Affairs / Pierluigi Paganini06-07-2026ShinyHunters leaked a 234 GB archive allegedly stolen from DentaQuest in the United States, potentially exposing data for about 2.6 million individuals.
Technadu / Lore Apostol07-27-2026Threat actors reportedly used leaked email addresses from ShinyHunters-linked breaches to send sextortion emails demanding Bitcoin, prompting recipient warnings not to respond or open attachments.
Tech Jacks Solutions Security Command Center / Tech Jacks Solutions06-17-2026UNC6395 claimed responsibility for an Eastman Kodak Company breach by June 18, 2026, warning of release of 2.2 million records tied to SaaS integrations.
Security Magazine05-19-20267-Eleven disclosed an April 8 data breach in Maine involving unauthorized access to franchise application systems, with ShinyHunters claiming responsibility.
Security Magazine / Jordyn Alger06-17-2026Kodak confirmed a ShinyHunters data breach claim on 2.2 million records, with a June 18 leak threat, after an unknown compromise method.
AI Weekly06-15-2026Council of Europe investigates a ShinyHunters dark web leak claim after a June 16 threat covering 429,000+ employee records allegedly exposed via an Oracle PeopleSoft zero-day campaign.
Pluang06-24-2026Madison Square Garden Entertainment faced class-action lawsuits after a hacker leak exposed 26 million customer records containing sensitive biometric data.
MS NOW07-24-2026Madison Square Garden temporarily disabled facial recognition during Taylor Swift's wedding as reporting raised concerns about private biometric surveillance and limited legal safeguards in US venues.
Kavout05-21-20267-Eleven confirmed a May 2026 ShinyHunters breach that exposed over 600,000 Salesforce records containing franchisee PII, with notices going to Maine and Massachusetts.
All About Cookies / Sara J. Nguyen07-10-2026French authorities arrested suspected individuals linked to ShinyHunters in 2025 after the group used social engineering and identity bypasses for large-scale data extortion.
Almeida Law Group06-06-2026Rockville Fuel and Feed Company Inc. disclosed May 11, 2026 discovery of a breach after network suspicious activity on April 1, 2026, with notifications issued June 5, 2026.
Architecture & Governance / Holt Hackney07-14-2026Carlos Avalos filed a class action in New York federal court against Madison Square Garden over an alleged ShinyHunters breach involving patron biometric and PII collection.
Kiteworks / Patrick Spencer05-20-2026ShinyHunters announced April 2026 access to Rockstar Games' Snowflake environment through Anandot, with vendor credential privilege described as the pivot enabling data exfiltration.
DoControl / Albert Louison07-03-2026Madison Square Garden Sports reported a ShinyHunters breach in New York, with alleged 46 GB data exfiltration beginning via EntraID and exposing potential facial recognition data.