TL;DR: Madison Square Garden Entertainment kept a Microsoft Word file called "Facial Recognition Activists.docx" inside its corporate file share. The document listed specific activists who had publicly criticized MSG's facial recognition system, paired with their tweets and comments, and was accessible to other MSG employees. Joseph Cox of 404 Media found the file inside a 45GB cache of MSG data that hackers stole and posted online this month, the same cache behind a separate round of MSG-related reporting earlier in June. The Hacker News thread hit 300 points and 88 comments by the 07:50 UTC June 24 cycle 2 read, an 18.3-hour-old thread with a 0.42 c/p ratio and no engagement shock at the 300-point threshold. Adam Schwartz, the EFF's privacy litigation director, was on the list. Schwartz called the breach "a good time for Madison Square Garden to stop subjecting its patrons to biometric surveillance" [1]. The 300-point cross is the engagement-signature of a reader-response phenomenon, not a fresh news spike: the dossier confirms what was already suspected about MSG's surveillance apparatus after the April 2026 Wired investigation documented a trans fan tracked for two years and an estimated 1,500 lawyers banned from MSG venues [2][3].

The Document

The file is named "Facial Recognition Activists.docx." It is a Microsoft Word document stored inside MSG's internal file share. The document pairs the names of specific activists with their public criticism of MSG's facial recognition system: tweets, public comments at MSG venues, op-eds, social media posts. The activists are listed by name and by the specific statements they made.

The document was inside a 45GB cache of MSG data that hackers stole and posted online earlier in June 2026. 404 Media downloaded the cache and reviewed it. Joseph Cox reported the document on June 23, 2026 [1]. Cox's reporting did not name all the activists on the list. He named Adam Schwartz of the EFF and reported that Schwartz was included because of his public criticism of MSG's facial recognition system, including his role in EFF's facial recognition litigation track. Cox's piece did not name the other activists on the list.

The document is dated sometime before the breach, but the breach itself was disclosed earlier in June when hackers posted the 45GB cache online. The cache included emails, internal documents, and security files. MSG acknowledged the breach in earlier reporting. The "Facial Recognition Activists.docx" finding is the most recent 404 Media report on the cache.

Per 404 Media, the document was accessible to "other people inside the company." MSG has not commented publicly on the document or the activists list. MSG's previous public statements about facial recognition have focused on the system's use for venue security and ticket-fraud prevention, not on monitoring critics [4][5].

Why This Document Is Different

MSG has been publicly known to use facial recognition technology since 2018 [2][3]. The company has separately faced criticism for banning an estimated 900 to 1,500 lawyers whose firms were in litigation against MSG, surveilling state officials, and hiring private investigators to tail government investigators [2][3]. The April 2026 Wired investigation by Pablo Torre and Noah Schachtman revealed a separate 18-page dossier compiled on a trans woman named "Nina Richards," tracking her bathroom breaks to the second during a Knicks game, and the broader MSG surveillance apparatus spanning MSG, Radio City Music Hall, and the Sphere [3].

The "Facial Recognition Activists.docx" file is the first publicly known internal MSG document that explicitly compiles a list of critics of the company's facial recognition system. The April 2026 Wired reporting documented the surveillance apparatus and a specific named target. The June 2026 404 Media reporting documents a categorical list of critics. The progression: MSG used facial recognition, MSG surveilled individual critics (the Wired piece), MSG compiled a list of all known critics (the 404 Media piece).

The list's existence inside MSG's internal file share also suggests it was used for cross-employee reference, not isolated to one security staffer's notes. MSG security personnel, MSG legal personnel, and MSG operations personnel could all access the file. The 404 Media report says the document was "accessible to other people inside the company." That framing matters: the dossier is not a rogue employee's personal notes. It is institutional record-keeping.

The distinction matters for the surveillance-state beat because the constitutional and statutory limits on government surveillance of critics do not apply to private actors. MSG is a private company operating its venues on private property. The First Amendment limits government surveillance of speech-related activity. It does not directly limit MSG's compilation of a list of activists who criticized MSG. The state-action doctrine that protects activists from government retaliation does not reach private corporate retaliation in the same way. The 404 Media story is, structurally, a story about the limits of state-action doctrine as a check on private biometric surveillance [6][7].

The EFF Response

Adam Schwartz, the EFF's privacy litigation director, confirmed his inclusion on the list to 404 Media. His quoted response to the publication: "The wake of a data breach would be a good time for Madison Square Garden to stop subjecting its patrons to biometric surveillance" [1].

The EFF's facial litigation track includes challenges to face-recognition systems used by FBI, ICE, and local police, and to corporate facial recognition use. Schwartz's bio on EFF's site confirms he has filed amicus briefs in Facebook biometric and Clearview AI cases and is the Privacy Litigation Director on EFF's Civil Liberties Team.[8] His inclusion on the MSG activists list indicates MSG's facial recognition surveillance team tracked the public advocacy and litigation strategy of the leading US facial-recognition critic organization.

Schwartz's statement, and the implicit context, is the closest thing to a public legal framing of the MSG activists dossier. The EFF has not, as of June 24, 2026, filed a lawsuit against MSG specifically over the dossier. EFF litigation tends to be deliberate and ground in concrete harms. The current EFF statement focuses on the public-policy angle: biometric surveillance at MSG venues should stop. A future EFF lawsuit is plausible but not yet signaled.

The MSG Pattern: From Surveillance to Suppression

The June 2026 404 Media report is the third major public disclosure about MSG's surveillance-and-suppression apparatus in twelve weeks. The April 2026 Wired investigation documented the surveillance apparatus, the 18-page Nina Richards dossier, and the banned-lawyers pattern [2][3]. The May 2026 reporting cycle surfaced additional details about MSG's use of Corsight facial recognition software. The June 2026 404 Media report documents the Facial Recognition Activists.docx dossier inside the breached cache.

The cumulative picture is a private actor operating a multi-modal surveillance apparatus and using it to track, profile, and restrict access to critics. The constitutional and statutory frameworks that constrain government surveillance do not, with limited exceptions, reach private actors operating on private property. The result is a parallel surveillance architecture that mimics the worst patterns of government surveillance without the legal constraints [10][11].

MSG is not the only private actor operating such an apparatus. The April 2026 Wired investigation named several corporate-surveillance vendors (eConnect, Xtract One, Corsight) whose technology stacks are deployed at sports venues, theme parks, and corporate campuses across the United States. The MSG reporting has become a focal case for the broader private-actor surveillance beat, but the underlying vendors and venues are far more numerous than MSG alone [12][13].

What's Being Done About It

The June 2026 404 Media report does not announce a new legal or regulatory response. The pattern of corporate-actor biometric surveillance of critics is governed by a patchwork of state biometric privacy laws (Illinois BIPA, Texas CUBI, Washington biometric law, a handful of others), venue-level terms of service, and the state-action doctrine limits on First Amendment claims against private actors [14][15].

Virginia's facial recognition law takes effect July 1, 2026, and restricts law enforcement use of the technology [9]. It does not directly restrict private-actor use. Illinois's HB 5521 would ban police use but, again, does not reach private actors [16]. The ICE Out of Our Faces Act (federal) would ban ICE and CBP use but does not reach private venues [15].

The MSG reporting does not, on its own, generate a discrete legal claim. The activists on the dossier are not arrested, not charged, not denied government services. They are potentially restricted from MSG venues, which is a private property decision. The constitutional protection against viewpoint discrimination in public accommodations does not extend to private venues in the same way. The legal floor for the MSG activists dossier is the same as for venue-admission decisions: property-owner discretion, constrained by state biometric privacy laws and public-accommodation statutes where they apply.

The political and reputational floor is different. The June 2026 404 Media report joins the April 2026 Wired report, the May 2026 follow-ups, and the underlying leaked 45GB cache as part of a rolling public record. Each cycle adds context. The cumulative record is now substantial. The reputational pressure on MSG is no longer the first-cycle shock of the April 2026 Wired piece; it is the steady accumulation of confirmatory evidence across multiple independent press cycles.

References

  1. 404 Media: Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition (Joseph Cox, June 23, 2026)
  2. Maximum Spy Garden: MSG Tracked a Trans Knicks Fan for Two Years (April 2026, Wired investigation summary)
  3. MSG Surveillance Tracked a Trans Fan and Banned 1,500 Lawyers (April 22, 2026, the underlying Wired investigation)
  4. Hacker News: Madison Square Garden compiled a list of activists against facial recognition (HN id 48644781, 300 points and 88 comments at the 07:50 UTC June 24 cycle 2 read, posted 2026-06-23T13:36:14Z by HN user cdrnsf, source URL https://www.404media.co/madison-square-garden-made-dossier-on-activists-who-opposed-facial-recognition/)
  5. Wired: Madison Square Garden's Surveillance System Tracked a Trans Woman's Bathroom Breaks (April 21, 2026, Pablo Torre and Noah Schachtman)
  6. At Least 12 Wrongful Arrests: Clearview AI's Casualty Count (the cumulative facial recognition wrongful-arrest record, including the parallel federal pattern)
  7. How to Defeat Facial Recognition (the defensive-mitigation piece for activists who want to understand the technical counters)
  8. EFF: Detroit Takes Important Step in Curbing the Harms of Face Recognition Technology (July 15, 2024, by EFF's Tori Noble. Describes the Detroit settlement requiring independent evidence before arrests based solely on face recognition matches)
  9. Virginia's Facial Recognition Law Takes Effect July 2026: What It Actually Restricts (the state-level statutory counterweight, effective July 1 2026)
  10. EFF: Biometric Surveillance (the EFF's institutional tracking of biometric surveillance, including the MSG reporting)
  11. ACLU: Privacy and Technology (the ACLU's institutional tracking of biometric surveillance litigation)
  12. 108 Days for a Face She Doesn't Have (the Angela Lipps wrongful arrest, the parallel federal-pattern wrongful-arrest case)
  13. IPVM: Police Chiefs Track (the Flock-powered police chiefs stalking investigation, a separate June 2026 private-actor surveillance beat)
  14. ACLU: Biometric Technologies (the ACLU's institutional tracking of biometric-privacy state laws)
  15. The ICE Out of Our Faces Act Would Ban Federal Face Scanning (the federal-level counter, focused on government use)
  16. Illinois Moves to Ban Police Facial Recognition As Chicago Credits It (the Illinois HB 5521 bill, the strongest state-level police-use ban; SOS tracker on the same Cassidy-authored vehicle that died in committee March 2026)