Star Tribune
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
The Star Tribune is an American news organisation that has come to public attention within cybersecurity discussions primarily because its user data was among multiple datasets illicitly offered for sale by a hacking collective known as Shiny Hunters. The incident in question occurred in May 2020, when Shiny Hunters publicly leaked and marketed stolen records from approximately 11 separate companies on a dark web marketplace. Within that broader cache, Star Tribune subscriber or user account records were reportedly included, alongside data from entities as varied as an Indonesian online retailer, an Indian e-learning platform, and a major technology firm whose private source code repositories were also exposed. The inclusion of the Star Tribune in such a multi-victim dump illustrates how regional news organisations can become collateral targets within wider third-party or supply-chain compromises, rather than being singled out as the primary focus of an attack.
The datasets sold by Shiny Hunters in that campaign were initially listed at prices ranging between $1,500 and $3,500 per individual database, with prices adjusted over time as additional tranches were released. Reports from the time noted that samples of the stolen records appeared legitimate, although complete forensic verification of the full content was still pending when the news was published. Some of the affected organisations confirmed the breaches and moved to notify their users, while others, including potentially the Star Tribune, were less responsive to direct inquiries from journalists, leaving the precise scope of impact on that organisation's user base unclear in publicly available reporting. This pattern of uneven response is typical in cases where a single threat actor aggregates credentials from many different sources and resells them as a portfolio.
From a structural standpoint, the provided context identifies the organisation only by its alias, "Star Tribune," and confirms that it is headquartered in the United States of America. No information is supplied regarding ownership structure, parent company, subsidiary relationships, employee count, circulation figures, or specific markets served beyond its national operating base. Consequently, any detailed profile of the organisation's editorial products, geographic reach, regulatory standing, or sector positioning cannot be constructed from the available material without risking speculation. The only verifiable fact tying Star Tribune to cybersecurity analysis is its appearance as one of the affected parties within the Shiny Hunters multi-organisation data leak of 2020, as documented in public reporting by BleepingComputer.
Given the deliberately limited scope of the source material, the confirmed profile is necessarily narrow: Star Tribune is a US-based organisation known in cybersecurity contexts chiefly through its inclusion among victims whose user data was marketed by the Shiny Hunters group in early May 2020.
Incidents
1 incident linked to this organisation.