SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
▣ Breach NEXSTAR-SHINYHUNTE 2026-06-11

Nexstar: ShinyHunters Salesforce Data Theft

"Nexstar Media Group, one of the largest television broadcasting companies in the United States, is investigating a potential cybersecurity incident after the ShinyHunters extortion group claimed to have stolen more than…"

Nexstar Media Group, one of the largest television broadcasting companies in the United States, is investigating a potential cybersecurity incident after the ShinyHunters extortion group claimed to have stolen more than 1.1 million Salesforce records along with additional internal corporate data. The threat actor listed "Nexstar.tv" on its extortion portal on June 11, 2026, framing the post as a "final warning" and setting a June 14, 2026 deadline for the company to make contact before the data is released. Nexstar has confirmed it is aware of the reports and "looking into it," while stating there is no disruption to its operations.

What Happened

ShinyHunters added Nexstar to its extortion site on June 11, 2026, alleging the compromise of "over 1 million Salesforce records and other internal corporate data containing PII." According to information the attackers shared with CyberInsider, the intrusion occurred on June 6, 2026. To support the claims, the group provided screenshots and data samples that appear to originate from Salesforce exports and internal corporate repositories.

No data has been publicly leaked yet. The posting follows the now-familiar ShinyHunters playbook: name the victim, publish a sample, set a short countdown, and pressure the organization into private negotiation before the deadline expires. Nexstar's spokesperson responded with a measured statement: "Nexstar is aware of reports of a potential IT security incident and is looking into it. There is no disruption to our operations." The company has not confirmed that a breach occurred, and the claims remain unverified at the time of reporting.

What Was Taken

The samples shared by the threat actor appear to show roughly 1.1 million account entries containing contact records and user databases. The dataset also reportedly includes employee-related information such as names, email addresses, job titles, office locations, and organizational details tied to Nexstar personnel.

Beyond the Salesforce exports, ShinyHunters claimed access to more than 6,300 SharePoint files and approximately 31 GB of internal data. If accurate, that scope would span both customer or business contact records and internal corporate documentation. These figures originate entirely from the attacker and have not been independently confirmed by Nexstar or third parties.

Why It Matters

Nexstar operates nearly 200 television stations across numerous US markets and owns national media assets including NewsNation and The CW Network. A confirmed breach of this scale would put a large pool of contact and employee PII at risk of resale, phishing, and follow-on social engineering.

The incident also fits a broader pattern. ShinyHunters has been linked to a wave of Salesforce-targeted data theft campaigns affecting major enterprises worldwide. For defenders, the recurring theme is that cloud CRM platforms holding millions of records have become a primary target, and a single compromised access path can expose an entire customer and employee database. Media organizations, with their large workforces and public profiles, make especially attractive extortion targets.

The Attack Technique

The specific intrusion vector at Nexstar has not been disclosed. However, ShinyHunters' recent Salesforce-focused campaigns have repeatedly leaned on social engineering and OAuth abuse rather than software exploits, including voice-phishing (vishing) of employees to obtain credentials or to trick staff into authorizing malicious connected apps that grant API-level access to Salesforce data.

Once a valid session or connected-app token is in hand, large-scale record exports can be performed through legitimate APIs, which makes the activity difficult to distinguish from normal business operations. The claimed haul of SharePoint files alongside Salesforce records suggests the attacker may have obtained broader corporate access beyond the CRM alone, though this remains unverified.

What Organizations Should Do

Sources: Nexstar investigates potential breach after ShinyHunters claims theft of 1.1M Salesforce records