On May 1, 2025, local CBS affiliate WDEF-TV in Chattanooga, Tennessee, appeared on the leak site of the lynx ransomware group. The station’s parent company, Morris Multimedia, confirmed that internal files had been exfiltrated during a ransomware incident. While the exact number of people whose personal information may have been exposed remains unknown, anyone whose records passed through the station — employees, contractors, news sources, or viewers who submitted information — may now be at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Wdef-Tv
Get alerted the next time Wdef-Tv files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Wdef-Tv’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that lynx actors breached WDEF-TV’s systems and removed internal documents. The leak site listing appeared on May 1, 2025. No precise count of affected records has been released, and the precise data types inside the exfiltrated files have not been fully detailed. Available reporting describes the incident as a classic ransomware attack that combined encryption with data theft for extortion.
Why This Matters for You and Your Family
When a local television station is breached, the impact reaches far beyond the newsroom. Employee records, vendor contracts, viewer contest entries, tip-line submissions, and advertising client information can all contain names, addresses, phone numbers, email accounts, and dates of birth. If your family has ever interacted with WDEF-TV — whether through a news tip, contest entry, employment application, or even routine billing — some of your information may now sit in files controlled by cybercriminals. Once stolen data leaves a company’s control, it circulates quickly on underground forums where it can be resold or used to target you directly.
The Doxxing and Identity-Chain Risks
Credential leaks from incidents like this rarely stay isolated. An email and password pair taken from one organization is tested against banking, email, social media, and gaming accounts. Children’s gaming profiles linked to a parent’s email or home address are especially vulnerable because kids often reuse simple passwords or family information. These connections create an identity chain that lets attackers move from a single breach to full doxxing — publishing your home address, phone number, family member names, and even children’s usernames in one public dump. Continuous monitoring across 13.1B+ breach records and 100+ platforms becomes essential because the first sign of trouble is often months after the initial theft.