Madison Square Garden Faces Three Class Actions After Cyber Attack

Plus, Texas AG investigating Carnival over data breach.

Good morning! Here’s what’s up.

People

Vikram Anbazhagan has joined Siemens as vice president of product, AI, bringing deep expertise in AI, generative AI, machine learning, and product leadership. Previously, he was a senior director for Security Copilot at Microsoft Security.

Clips ✂️

Customers Sue Madison Square Garden Over Hacking of 26 Million Records

In the days before the Knicks won the N.B.A. finals, sending New York City into a rapture, a hacking group was quietly working to steal data from Madison Square Garden, including the records of celebrities and other customer information, according to three class-action lawsuits filed against the companies that own the arena and sports teams.

ShinyHunters, a hacking group, claimed responsibility for the attack and announced on June 12 that if it did not receive a ransom from the Garden, more than 26 million records would be leaked.

On June 16, ShinyHunters sent a new message: “It’s very simple. When you pay us, your data is deleted, and you move on with your life. When you don’t pay us, you get posted here, among other things.”

That same day, the hackers published the records after announcing that Madison Square Garden had “failed to reach an agreement with us,” according to the lawsuits, which were filed last week in the Southern District of New York.

by The New York Times

Paxton announces investigation into Carnival over data breach that affected 800K Texans

Texas Attorney General Ken Paxton says his office is investigating a data breach at Carnival Cruise Line that the company says affected about six million customers, including roughly 800,000 Texans.

KHOU 11 first reported on the breach in May after Carnival began notifying customers that their personal information had been compromised in a cybersecurity incident that was discovered April 14. According to the cruise line, an employee was tricked by social engineering, allowing an unauthorized person to get access to customer data.

“I am investigating the Carnival Cruise Line data breach to ensure that the company is held accountable for any illegal action and that Texans' private information is properly secured,” Paxton said in a news release issued Monday. “Data breaches are a serious matter, and my office is committed to protecting Texans’ sensitive personal information.”

The attorney general's office did not provide additional details about the investigation or say what specific laws may have been violated.

by khou.com

Hyundai and Kia create TED's first cybersecurity group

Hyundai Motor and Kia have launched a cybersecurity working group within the Korea-U.S.-Japan Trilateral Executive Dialogue (TED), the forum’s first topic-specific subgroup. The initiative aims to build a coordinated, private sector-led defence framework as AI-era cyber threats grow more sophisticated and cross-border supply chain vulnerabilities multiply.

The TED brings together government and business leaders from South Korea, the United States and Japan to discuss economic development and national security cooperation. Hyundai Motor and Kia have been sponsors since 2023, and led the creation of the cybersecurity subgroup as TED’s first focused topic area.

The group will hold regular seminars at which member companies can exchange security trends, operational experience and best practices. Its inaugural session, hosted at Hyundai Motor Group’s Seoul headquarters, examined security challenges in the AI era, covering threats facing automotive, robotics and smart factory systems.

by Automotive World

AI-Enabled Vulnerability Discovery: What Next-Gen Tools Mean for the Management of Cybersecurity Risk

Regulatory bodies around the world are sounding the alarm as the latest generation of artificial intelligence (AI) models has demonstrated the ability to not only identify thousands of previously unknown high- and critical-severity vulnerabilities in a matter of minutes but also autonomously exploit them.

Many of these vulnerabilities had remained undetected by experienced human researchers and hackers for years. As they are identified simultaneously across the existing installed software base globally, experts are recommending that businesses prepare for a coming “patch wave,” which is expected to overwhelm existing protocols to patch vulnerabilities.

For corporate leaders, AI-enabled cybersecurity is both an opportunity and a looming threat: The same tools that promise faster, more comprehensive discovery of defects can be turned against unpatched systems at record speed and scale.

by Skadden

How businesses can respond when hackers steal Data

When a cyberattack results in the theft of sensitive information, one of the first questions asked by affected organizations is whether the stolen data can be deleted from the hackers’ servers.

Unfortunately, the answer is rarely straightforward. Once data has been exfiltrated from a compromised network, organizations lose direct control over where that information is stored, copied, or distributed. However, there are several steps that can be taken to reduce the impact of the breach and, in some cases, facilitate the removal of stolen data from online platforms.

The first step is to confirm the scope of the breach through a forensic investigation. Incident response teams need to determine what information was stolen, how the attackers gained access, and whether the data has already been published or sold. Understanding the extent of the compromise allows organizations to prioritize response efforts and protect affected individuals.

by Cybersecurity Insiders

How to Build a High-Performing Cybersecurity Team for Your Business

Most businesses think having the right security tools means they have security covered. A firewall here, an antivirus solution there, maybe a SIEM if they feel ambitious. But if you look at the organizations that suffer the most damaging breaches, the gap is rarely the technology. It is the people and structure behind it.

Building an effective cybersecurity team is not about headcount. It is about having the right functions covered, the right skills in place, and a culture where security is treated as a business priority at every level. Whether you are starting from scratch or trying to mature an existing information security team, the principles are the same: structure first, skills second, and continuous investment throughout.

Here is how to approach each step.

by Security Boulevard

X