Back to Blog
2026-06-24· 5 min read

How Hackers Broke into Madison Square Garden: 45GB Stolen via Vishing Attack

Hackers stole 45GB of data from Madison Square Garden by calling a low-level employee and tricking them into granting access. The attack highlights the growing threat of vishing.

Social Engineering Vishing Data Breach Sports New York

The Attack


Hackers stole more than **45GB of data** from Madison Square Garden (MSG), including sensitive data related to "talent" and the New York Knicks basketball team. The attackers gained access through a simple phone call.


How Vishing Works


**Vishing** (voice phishing) is social engineering over phone calls. Unlike email phishing, vishing:


  • Feels more personal — victims hear a real voice
  • Creates urgency — live conversation pressures quick decisions
  • Bypasses email filters — no malicious links or attachments
  • Exploits trust — people are more trusting of callers

  • The Attack Chain


    1. **Attacker called** a low-level MSG employee

    2. **Convinced the employee** to grant system access

    3. **Gained entry** to MSG's internal systems

    4. **Exfiltrated 45GB** of data

    5. **Left with**: Talent data, Knicks information, and other sensitive files


    Why Vishing Is Increasing


    Young, Native English Speakers

    The cybersecurity community has noted that vishing has become more prevalent as young, native English-speaking hackers have become a serious threat. They can:


  • Make convincing phone calls without accent concerns
  • Use social engineering techniques in real-time
  • Sound like legitimate IT support or vendors

  • AI-Powered Voice Deepfakes

    Emerging threats include:

  • AI voice cloning to impersonate executives
  • Real-time voice synthesis during calls
  • Automated vishing campaigns at scale

  • Protecting Your Organization


    Employee Training

  • Verify caller identity before granting access
  • Use callback procedures — hang up and call back on official numbers
  • Never share credentials over the phone
  • Report suspicious calls to security team

  • Technical Controls

  • Multi-factor authentication for all access requests
  • Call-back verification for sensitive requests
  • Phone system security — block spoofed numbers
  • Access logging for audit trails

  • Policy Improvements

  • No access grants based solely on phone requests
  • Verification procedures for IT support calls
  • Regular vishing simulations to test employees
  • Clear escalation paths for suspicious contacts

  • The Cost of Social Engineering


    MSG's breach demonstrates that:


    1. **Technology alone isn't enough** — humans are the weakest link

    2. **Low-level employees** can be gateway to major breaches

    3. **Simple attacks** can be devastating

    4. **Training is investment**, not expense


    Check Your Domain


    Scan your domain for vulnerabilities and security misconfigurations.


    [Free security scan at Vaarta.space](https://vaarta.space)


    Ready to check your domain security?

    Run a free scan to identify potential vulnerabilities.

    Start Free Scan