Ransomware victim disclosure
← All victimsNexstar Media Group, Inc.
listed as Nexstar.tv · Claimed by Shinyhunters · listed 4 days ago
Status timeline
- ListedJun 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jun 11, 2026
About the victim
AI dossier — public-source company profileNexstar Media Group, Inc. (NASDAQ: NXST) is the nation's largest local television and media company, operating 201 TV stations across 116 markets reaching over 70% of U.S. households. The company produces and distributes local and national news, sports, and entertainment content across television and digital platforms, with over 13,000 employees and $5.41 billion in 2024 net revenue.
- Industry
- Broadcast & Digital Media
- Employees
- 13000
- Founded
- 1999
Attack summary
Severity: critical — Confirmed exfiltration of over 1 million records containing PII from a major publicly-traded media company with national infrastructure reach; data includes internal corporate records from a systems-of-record platform (Salesforce).ShinyHunters claims to have compromised over 1 million Salesforce records and internal corporate data containing personally identifiable information (PII). The group issued a final warning dated 11 June 2026 threatening to publish the data by 14 June 2026 if contact was not made.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce records (1M+)
- Internal corporate data
- Personally identifiable information (PII)
What the group claims
Over 1 million Salesforce records and other internal corporate data containing PII was compromised. This is a final warning to reach out by 14 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 June 2026 | Warning: FINAL WARNING
Sources
- Victim siteNexstar.tv
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

