
MSG Data Breach Timeline: Cl0p, ShinyHunters, and the 45GB Dump
The Madison Square Garden breach timeline: Cl0p's Oracle attack, ShinyHunters' 45GB dump, biometric records, and what was in the leaked files.

The Madison Square Garden breach timeline: Cl0p's Oracle attack, ShinyHunters' 45GB dump, biometric records, and what was in the leaked files.

AI events develop and spread significantly faster than traditional reputation crises. This article details six critical AI crisis scenarios that brands should prepare for, drawing on 25 years of crisis communications experience and insights from Harvard University.

Fifteen years of defining breach communications cases — Equifax, T-Mobile, PayPal, MOVEit, MGM, Change Healthcare — and the playbook every response team runs against.

The December 2022 PayPal credential-stuffing breach accessed approximately 35,000 customer accounts using credentials stolen from unrelated breaches on other platforms. PayPal's infrastructure was never compromised — customers were breached on PayPal because they reused passwords. The canonical fintech credential-stuffing case study.

T-Mobile disclosed a breach affecting ~40M former/prospective customers, 7.8M current postpaid, and 850K prepaid — SSNs, DOBs, driver's license data exposed. The fifth breach in four years. Mike Sievert's response and the pattern regulators are watching.

The Equifax breach still teaches two lessons: an insider trading charge that redefined disclosure-window doctrine, and a reputation file that never closed even after the stock price fully recovered.

RockYou's 2009 breach exposed 32M plain-text passwords. The leaked list became the foundation of modern password security — still used in 2026 to crack the RockYou2024 megabreach.