Nexstar investigates potential breach after ShinyHunters claims theft of 1.1M Salesforce records

How Safe Is Your Digital Life?

Seven questions. Two minutes. Find out if a breach like this one could seriously hurt you.

Do you use the same password — or slight variations of it — across multiple accounts?

Do you use a password manager?

Do you have two-factor authentication (2FA) enabled on your email and financial accounts?

Do you monitor whether your email address has appeared in known data breaches?

Have you ever used a work or corporate email address to sign up for personal apps, newsletters, or subscriptions?

You receive an urgent email from 'IT Security' asking you to verify your login immediately due to a recent breach. What do you do?

How much personal information do you typically share when signing up for services, apps, or loyalty programs?

That quiz measures exactly the kinds of vulnerabilities that make breaches like this one dangerous for ordinary Americans. The Nexstar incident isn't just a corporate IT story — when a company that operates nearly 200 local TV stations has its employee and customer data potentially exposed, the ripple effects reach far beyond a single corporate headquarters.

ShinyHunters is no newcomer. The group has been linked to some of the largest data theft operations in recent memory, including the massive AT&T breach and the Ticketmaster hack that compromised hundreds of millions of records. Their method is consistent: steal data, publish a claim, share samples to prove it, then pressure the victim to pay before releasing everything publicly.

The Nexstar Breach: What We Know So Far

What's True, What's Unconfirmed

ShinyHunters stole more than 1.1 million records from Nexstar.

Verdict: unverified

The group has published the claim and shared data samples with reporters that appear to contain employee and contact information. However, Nexstar has neither confirmed nor denied the breach, and the samples have not been independently verified. Claims of breach scope are often inflated in extortion campaigns.

Nexstar's operations have been disrupted by this incident.

Verdict: false

Nexstar's official statement explicitly says 'there is no disruption to our operations.' Whether a breach occurred is separate from operational disruption — both can be true simultaneously.

ShinyHunters is a credible and active threat group.

Verdict: true

ShinyHunters is a well-documented cybercrime group responsible for multiple confirmed high-profile breaches including AT&T and Ticketmaster. Their tactics — claim, sample, pressure, release — follow a consistent and documented pattern.

If you've ever contacted a Nexstar TV station, your data is definitely compromised.

Verdict: false

The alleged stolen data appears focused on internal corporate Salesforce records — primarily employee and business contact data. The full scope of what was taken, if anything was, is not yet confirmed. Do not assume personal viewer data was exposed based on current reporting.

The ShinyHunters playbook is deliberately designed to maximize pressure. Publishing a 'final warning' with a tight deadline forces companies into a painful choice: pay quietly and risk emboldening attackers, or refuse and watch sensitive employee data get dumped publicly. It's a business model, and it has worked against some of the world's largest companies.

For American workers whose employers use platforms like Salesforce and SharePoint — which is nearly every major company — incidents like this serve as a reminder that your professional profile exists in dozens of corporate databases you've never thought about. Your job title, office location, work email, and organizational chart position are all valuable data points to attackers crafting targeted phishing campaigns.

ShinyHunters: Known vs. Alleged Attacks

TargetRecords ExposedStatus
AT&TAT&T~73 millionConfirmed breach
TicketmasterTicketmaster560+ millionConfirmed breach
Nexstar Media GroupNexstar Media Group1.1M claimedUnder investigation

What To Do Right Now If You're Worried

  1. Check if your email was exposed — Visit HaveIBeenPwned.com and enter your email address. It's free, takes 30 seconds, and will show you every known breach your email has appeared in — including any Nexstar-related data once it's confirmed.
  2. Change passwords for accounts using your work email — If you've used a work email to sign up for any personal services, change those passwords now — especially if you reuse passwords. Start with email, banking, and any account tied to your identity.
  3. Enable two-factor authentication — Go to the security settings of your email and banking apps and turn on 2FA immediately. Use an authenticator app (Google Authenticator, Authy) rather than SMS if the option is available.
  4. Be suspicious of urgent security emails — After any major breach announcement, phishing emails posing as security alerts surge. If you receive an email asking you to 'verify your account' due to a breach, delete it and navigate directly to the website yourself.
  5. Set up a free password manager — Bitwarden is free, open-source, and takes about 10 minutes to set up. It generates unique passwords for every account and stores them securely — eliminating the biggest single vulnerability in most people's digital lives.

Here's the uncomfortable truth that the Nexstar investigation underscores: most Americans are only one corporate breach away from having their professional and personal information circulating on criminal marketplaces. The company holding your data doesn't have to be one you've heard of — it just has to be one your employer, doctor, or local news station uses.

Your quiz score from above reflects exactly the gap between where most people are and where security experts say they need to be. The good news is that the five steps above are genuinely achievable this week, for free, and they would protect you against the most common attacks that follow breaches like this one.

Protect Yourself — Free Resources

Who Is ShinyHunters — And Why Do They Keep Winning?

ShinyHunters emerged as a major cybercrime group around 2020 and has since become one of the most prolific data theft and extortion operations in the world. Unlike ransomware groups that encrypt systems and demand payment to restore them, ShinyHunters specializes in exfiltration — stealing data quietly and then leveraging the threat of public release to extort payment.

Their targets have included some of the largest companies on earth, and their success rate at extracting settlements is believed to be significant — though victims rarely disclose payments publicly. The group typically operates by purchasing or discovering access credentials, navigating internal systems to locate high-value data repositories like Salesforce CRM exports and SharePoint file stores, and exfiltrating large datasets before anyone notices.

What makes ShinyHunters particularly effective is their media strategy. By sharing credible-looking samples with cybersecurity journalists, they create urgency and legitimacy for their claims — even when the full breach is not yet confirmed. This pressures victims' legal and communications teams simultaneously, often before the IT investigation is even complete.

The group's activities highlight a structural vulnerability: major enterprise platforms like Salesforce store enormous concentrations of sensitive data, and a single compromised credential or misconfigured API can expose millions of records at once.

Sources & References

Open the interactive version »