LexisNexis Takes Key Services Offline Following Third-Party Vendor Security Incident
LexisNexis, a leading global data analytics provider, temporarily disabled its Diligence, Metabase API, and Newsdesk services after detecting unusual activity on servers managed by an unnamed third-party vendor. The company acted swiftly to contain the threat, disconnecting from the affected systems while investigating the incident with the support of a cybersecurity forensic firm.
In a customer notification last week, LexisNexis confirmed the disruption, stating that it was rebuilding impacted systems in a new environment before restoring services. Todd Larsen, President of LexisNexis’s global Nexis Solutions division, told BleepingComputer that the investigation remains ongoing, with remediation efforts underway.
The outage affected critical platforms:
- Nexis Diligence: A due diligence and risk research tool used by compliance professionals.
- Nexis Metabase API: A data feed service for enterprise news and media integration.
- Nexis Newsdesk: A media monitoring and analytics platform for PR and marketing teams.
LexisNexis clarified that the incident was unrelated to a recent Metabase Cloud zero-day SQL injection vulnerability, which had been exploited in data-theft attacks. Larsen confirmed that the company does not use Metabase Cloud and that its Nexis Metabase API operates independently of the affected service.
This incident follows two prior breaches in 2025:
- May 2025: Hackers stole personal data of 364,000 individuals after infiltrating private GitHub repositories.
- March 2025: The threat actor FulcrumSec exploited the React2Shell flaw in LexisNexis’s AWS infrastructure, leaking private files though the company stated the compromised servers contained mostly legacy data.
LexisNexis serves a broad client base, including corporations, law firms, financial institutions, and government agencies, making its security posture a critical concern for high-risk industries. The latest disruption underscores the growing risks of third-party vendor dependencies in enterprise cybersecurity.
LexisNexis I Nexis Solutions International cybersecurity rating report: https://www.rankiteo.com/company/nexis-solutions-internationalsales
"id": "NEX1786372617",
"linkid": "nexis-solutions-internationalsales",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Data Analytics, Legal, Financial, '
'Government',
'name': 'LexisNexis',
'type': 'Corporation'}],
'customer_advisories': 'Customer notification sent',
'description': 'LexisNexis, a leading global data analytics provider, '
'temporarily disabled its Diligence, Metabase API, and '
'Newsdesk services after detecting unusual activity on servers '
'managed by an unnamed third-party vendor. The company acted '
'swiftly to contain the threat, disconnecting from the '
'affected systems while investigating the incident with the '
'support of a cybersecurity forensic firm.',
'impact': {'operational_impact': 'Services temporarily disabled; rebuilding '
'impacted systems in a new environment',
'systems_affected': 'Diligence, Metabase API, Newsdesk'},
'investigation_status': 'Ongoing',
'references': [{'source': 'BleepingComputer'}],
'response': {'communication_strategy': 'Customer notification',
'containment_measures': 'Disconnected from affected systems',
'incident_response_plan_activated': 'Yes',
'recovery_measures': 'Restoring services',
'remediation_measures': 'Rebuilding impacted systems in a new '
'environment',
'third_party_assistance': 'Cybersecurity forensic firm'},
'title': 'LexisNexis Takes Key Services Offline Following Third-Party Vendor '
'Security Incident',
'type': 'Third-party vendor security incident'}