ハッカーがニューヨーク・ニックスとマディソン・スクエア・ガーデンのデータをオンライン上に公開
本文の状態
日本語全文を表示中
詳細モードで約4分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
404 Media
ハッカー集団が、マディソン・スクエア・ガーデンから顧客個人情報を含むデータを窃取し、誰でもダウンロード可能な状態でオンライン上に公開した。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
imageハッカーらは、マディソン・スクエア・ガーデンから窃取したデータをオンライン上に公開し、誰でもダウンロードできるようにしました。そこには顧客の個人情報も含まれているとされています。404 Media が検証したサンプルファイルには、特定のスポーツチームや、特にニューヨーク・ニックスに関連する人物の名前が記載されており、「住所」、「著名な業績」、「タレントのコスト」、あるいは彼らやその代理人の連絡先情報などの項目が含まれています。
「非常にシンプルです。私たちに支払えば、あなたのデータは削除され、あなたは人生を続けます。支払わなければ、ここでは他のものとともに公開されます」と、ハッカーらのウェブサイトのポップアップメッセージには記載されています。このデータを公開しているのは ShinyHunters というグループで、過去数年間にわたり一連のセキュリティ侵害事件を引き起こしてきた組織です。
今回のデータ流出は、ニックスがサンアントニオ・スパーズとの NBA ファイナルを 5 ゲーム制で制覇した直後のことです。実際の侵害はこの勝利よりも前に発生していた可能性が高いですが(ハッカーグループのスポークスマンは侵害が 6 月 5 日に発生したと述べています)、ニックスの優勝により、彼らと MSG に対する注目が大幅に高まりました。
このセキュリティ侵害について他に何かご存知ですか?ぜひお聞かせください。職場用の端末ではなく、非業務用のデバイスから、Signal で joseph.404 までメッセージを送るか、joseph@404media.co までメールをお送りください。
ShinyHunters は火曜日に MSG のデータを公開しました。完全なファイルのダウンロード量は約 45GB に及びます。このグループのスポークスパーソンは、404 Media に対してデータの小さなサンプルを送付しました。その中の一つのファイルには、顧客から MSG へ送られたメールや、場合によっては MSG からの返信が含まれているようです。ある一通のメールでは、MSG の顔認識システムによって誤ってマークされた可能性を訴える男性の投稿が見られます(MSG のオーナーであるジム・ドランは長年自らのアリーナ内の人間を監視しており、WIRED によると MSG はさまざまな監視技術を導入しています)。
サンプルにはファイル名に「Talent」という言葉が含まれるものがあり、そこにはスポーツ界の著名な人々の長いリストが記載されていました。これには MSG の執行役員の家族、元ニューヨーク・ニックス選手およびヘッドコーチ、そして有名人が含まれています。
巨大なニックスファンであり、最近の NBA ファイナル戦で MSG に訪れていたベン・スティラーもこのファイルに含まれています。連絡先情報として記載されているのは、スティラーが運営する制作会社「Red Hour Films」のメールアドレスです。
このファイルではスティラーを「Low Risk(低リスク)」と分類していますが、ファイル自体からはその意味が明確ではありません。ファイル内で「High Risk(高リスク)」とリストされている人物はたった一人だけで、それはラッパーの A Boogie wit da Hoodie です。
MSG はコメント依頼に対して直ちに回答していません。ShinyHunters のウェブサイトによると、MSG は要求された身代金を支払っていません。
3 月、MSG は Oracle の E-Business Suite ユーザーを対象としたデータ侵害(data breach)を受けたことを確認しました。SecurityWeek の報道によると、このハッキングキャンペーンでは Cl0p ランサムウェアグループが関与していました。同レポートはさらに、これらのハッカーらが 2025 年 11 月に MSG を特定の被害者として名指ししたと付け加えています。
原文を表示
imageHackers have published data stolen from Madison Square Garden online for anyone to download, including what they say is customers’ personal information. A sample reviewed by 404 Media includes files mentioning specific sports teams, and specifically Knicks-related personalities, with fields such as “address,” “claim to fame,” “cost of talent,” and sometimes contact information for them or their representatives.
“It’s very simple. When you pay us, your data is deleted, and you move on with your life. When you don’t pay us, you get posted here, among other things,” a popup on the hackers’ website reads. The group publishing the data is ShinyHunters, which has been responsible for an array of breaches over the years.
The data dump comes just days after the Knicks won the NBA Finals in five games against the Spurs. Although the breach likely happened before that—a spokesperson for the hacking group said the hack was on June 5—the Knicks’ victory has put a huge amount of attention on them and MSG.
Do you know anything else about this breach? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.
ShinyHunters published the MSG data on Tuesday. The full file download is nearly 45GB. A spokesperson of the group sent 404 Media a smaller sample of the data. One file includes what appear to be emails sent by customers to MSG and sometimes MSG’s response. One email is a man complaining about potentially being flagged by MSG’s facial recognition systems (MSG owner Jim Dolan has long spied on people inside his arenas, with MSG deploying various surveillance technologies, WIRED reported.)
The sample included a file with “Talent” in the filename, then a long list of high profile people in the sports world. It includes family members of MSG executives, former New York Knicks players and head coaches, and celebrities.
Ben Stiller, a huge Knicks fan and who was at MSG for the Knicks’ recent NBA finals games, is also included in the file. The contact information is an email address for Red Hour Films, the production company Stiller runs.
The file lists Stiller as “Low Risk,” although it's not clear from the file itself what that means. Only one person in the file is listed as “High Risk”: rapper A Boogie wit da Hoodie.
MSG did not immediately respond to a request for comment. The ShinyHunters website indicates MSG did not pay a demanded ransom.
In March MSG confirmed it had suffered a data breach which targeted users of Oracle’s E-Business Suite. In that hacking campaign, the Cl0p ransomware group was responsible, SecurityWeek reported. Those hackers named MSG specifically as a victim in November 2025, the report added.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み