MSG's Secret Celebrity Database Tagged Nearly 40,000 People by Sexuality, Race, and 'Risk' Level

A data breach at Madison Square Garden exposed an internal tracking list that sorted celebrities, public figures, and ordinary visitors using labels including 'LGBTQIA,' 'DO NOT HOST,' and a personal 'risk' score.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A large modern sports arena exterior at night, its glass facade reflecting city lights
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • A database breach at Madison Square Garden Entertainment exposed records on nearly 40,000 individuals, according to reporting by WIRED.
  • Internal labels included 'LGBTQIA,' 'DO NOT HOST,' and a 'risk' level assigned to each person.
  • MSG owner James Dolan's company disputes the accuracy of the WIRED report.
  • People who visited MSG venues may have had personal characteristics recorded without their knowledge.

Madison Square Garden, the New York City arena owned by James Dolan's MSG Entertainment, kept a secret internal database cataloguing nearly 40,000 celebrities and other individuals by their sexuality, race, and a personally assigned 'risk' score. That finding comes from WIRED, which obtained records from a breach, meaning an unauthorised leak of data from the company's internal systems.

WIRED contributing editor Noah Shachtman discussed his findings on CBS News. The database reportedly carried labels such as 'LGBTQIA' and 'DO NOT HOST,' the latter suggesting some people were flagged to be turned away at the door. Each entry also carried a 'risk' level, though the report doesn't specify how that score was calculated or who assigned it.

How did this information get out?

A breach of MSG's systems exposed the database to outside view. A breach is when someone without permission accesses a company's private files, either by hacking in or through an insider leak. The source article doesn't detail how the breach occurred or who carried it out.

MSG told WIRED the report is inaccurate. The company hasn't said which specific details it contests, and no statement has corrected any individual claim.

What makes this unusual isn't the hacking itself. It's what the hack revealed. Companies collect customer data routinely, but cataloguing individuals by sexual orientation or race and assigning a 'risk' label raises immediate questions under New York privacy law. This sits alongside a broader pattern we've been tracking: our 9 July story on Meta generating images of real people without consent covered the same uncomfortable territory of personal data collected or used without agreement.

Legal experts who spoke to WIRED noted that storing personal characteristic data without clear consent could expose MSG to civil liability.

Should you worry?

If you've attended an event at any MSG venue, your name may appear in a system you never knew existed, alongside tags you never agreed to. Submit a data access request to MSG Entertainment in writing, asking what personal data the company holds about you. Under some state privacy laws, companies must respond. Also watch for phishing attempts, where criminals send fake messages pretending to be from MSG or related services, using the breach as a hook to steal passwords or payment details.

The real story here isn't the breach mechanics. It's that a major entertainment company appears to have been quietly sorting visitors by protected characteristics for reasons it still won't explain.

© 2026 Threat Vectr