Simon Glairy is a preeminent figure in the landscape of insurance and Insurtech, recognized for his deep understanding of how emerging technologies transform corporate risk management. With a career spent analyzing the intersection of artificial intelligence and liability, he provides a unique perspective on the vulnerabilities that modern entertainment giants face when they prioritize surveillance over data hygiene. His expertise is particularly relevant in light of the massive security breach involving one of the world’s most iconic sports and entertainment organizations, where the line between guest services and invasive monitoring became dangerously blurred. In this discussion, we examine the fallout from a data spill that exposed not just contact information, but a sophisticated, internal system of categorization that labels visitors based on their public loyalty and personal identities.
The following conversation explores the internal mechanics of a “talent” database containing nearly 40,000 entries and the subsequent exposure of a customer management system housing over 10 million records. We delve into the implications of using social media sentiment to assign risk levels to high-profile figures, the ethical concerns surrounding the tracking of sensitive identifiers like sexual orientation, and the technical failures that allowed a criminal collective to walk away with 45 gigabytes of sensitive data. Through Glairy’s expert lens, we unpack how “vishing” attacks and the over-retention of customer data have created a perfect storm for litigation and reputational damage in the heart of New York City.
How do you interpret the strategy of assigning specific risk levels—ranging from low to high—to hundreds of celebrities and superfans, and what does this reveal about the modern corporate approach to risk management?
The decision to categorize roughly 400 celebrities out of a broader talent database of 39,539 entries indicates a shift from traditional security toward a more proactive, and perhaps paranoid, form of brand protection. When you look at the designations, it’s clear that “risk” in this context isn’t just about physical threats, which are handled in a separate database, but rather about “SM concerns” or social media reputation. For instance, seeing a “medium risk” label attached to a loyal superfan like Fat Joe—simply because of his proximity to other critics like Jadakiss—suggests that the organization is using surveillance to curate a compliant environment. This system, which ranks people from a simple “flag” to “low,” “medium,” and “high” risk, creates a chilling effect where even the slightest public criticism, like complaining about a gate entry experience, can lead to a “DO NOT HOST” status. It feels less like a security protocol and more like a digital scoreboard for loyalty, where icons like Pete Rock find themselves barred from complimentary tickets because they dared to call for a boycott on social media.
The database surprisingly included tags for sexual orientation and gender identity, as well as tracking political affiliations; what are the legal and ethical liabilities for a venue when it collects such sensitive personal data?
From an insurance and liability standpoint, maintaining a list that explicitly marks 93 entries as “LGBTQIA” or tracks the sexual orientation of artists like Phoebe Bridgers and Ricky Martin is an immense red flag. There is rarely a legitimate business justification for an arena to track the gender identity or sexual orientation of its guests, and doing so opens the door to claims of discrimination and privacy violations. Furthermore, the database tracks 32 political candidates supported by the organization’s PAC and nearly 60 people who supported specific permit renewals, suggesting that “complimentary tickets” are being used as a currency for political leverage. This type of data collection is what legal experts call a “mountain of data” that a company never truly needed, and when it spills, it exposes a pattern of behavior that can be used against them in massive class-action lawsuits. When you combine this with the minute-by-minute surveillance of vulnerable groups, you aren’t just managing risk; you are actively manufacturing it through over-collection and unnecessary profiling.
In the wake of a breach that exposed over 10 million records, including nearly 9.8 million unique emails, how should major corporations view the trade-off between “big data” marketing and the risk of a catastrophic hack?
The sheer scale of this leak—containing 9,782,361 unique emails and 2,820,221 unique phone numbers—is a staggering reminder that every piece of data retained is a potential liability waiting to be exploited. Many organizations fall into the trap of believing that more data always equals more value, but as we saw with the 45 gigabytes of data dumped by the hacker group, that data often becomes the very thing that fuels extortion. The fact that the database included information dating as far back as 2012, with updates as recent as early June, shows a failure to implement proper data-purging protocols. When a criminal collective can access a Salesforce system and pull the birth dates of 2,956 people along with the personal home addresses and phone numbers of high-ranking officials like the current NYPD commissioner, the reputational damage is nearly impossible to calculate. Organizations must realize that if they cannot secure a customer list, they have no business implementing invasive technologies like facial recognition across their venues.
The methodology behind this specific breach involved “vishing” and targeting Microsoft Entra systems; what does this tell us about the current state of cybersecurity and the human element in high-stakes environments?
It is a sobering reality that despite multimillion-dollar investments in cybersecurity, a simple “vishing” attack—or voice phishing—was enough to bypass the defenses of a major global enterprise. By using a bogus voice call to trick a junior employee into a password reset on Microsoft Entra, the hackers were able to burrow directly into the core of the organization’s network. This incident highlights a critical gap where “employee vishing” remains one of the most effective tools for criminal collectives, even as companies were warned by experts as early as January 2026 to restrict self-service password portals. The hackers were even able to access a folder marked “personal” containing sensitive tax documents of a junior staffer, proving that once the perimeter is breached, no corner of the network is safe. It shows that security is only as strong as its most tired or least-informed employee, and that “vishing” has become the preferred key for unlocking the world’s most guarded Salesforce databases.
What is your forecast for the future of biometric data and corporate accountability in the wake of such public disclosures?
We are entering an era where the public and the legal system will no longer tolerate the “surveillance state” approach to hospitality, especially when corporations prove they cannot safeguard the resulting data. As more cities see legislation introduced to ban the collection of biometric data—much like the bill cosponsored by the New York City mayor—we will see a massive pushback against the use of facial recognition at venue entrances. The irony here is that while the organization was busy scanning faces to build blacklists, they were losing the battle to protect the most basic contact information of 10.5 million people. My forecast is that we will see a “privacy-first” shift in the insurance market, where premiums for venues will skyrocket unless they can prove they have minimized their data footprint and moved away from the “paranoid” tracking of fan sentiment. The era of the all-seeing, all-tracking arena owner is being challenged by the reality that in Gotham City, the people—and the hackers—eventually find a way to flip the script.
