LexisNexis Takes Key Services Offline Following Third-Party Server Incident
LexisNexis temporarily disabled its Diligence, Metabase API, and Newsdesk services last week after detecting "unusual activity" on servers managed by a third-party vendor. The company proactively disconnected the affected systems to contain the issue and protect customer data while an investigation continues.
In an internal communication obtained by The Register, Todd Larsen, president of Nexis Solutions, stated the decision was made to "ensure the integrity of [LexisNexis’] environment" despite the resulting outages. The disruption began on Wednesday and persisted through the weekend, with Diligence partially restored over the weekend and Newsdesk and Metabase API expected to return progressively by Monday pending successful testing.
Affected customers, some of whom pay tens of thousands annually for these services, have indicated plans to seek compensation due to the disruption. Nexis Diligence supports background and compliance checks, Newsdesk provides news monitoring, and the Metabase API delivers near-real-time news and social media content (unrelated to the Metabase business intelligence platform).
LexisNexis confirmed the incident was not linked to the critical SQL injection flaw (CVSS 10.0) disclosed by Metabase on August 6, which has already been exploited in at least one breach. The company also clarified that its Metabase API product is unrelated to Metabase Cloud or the reported vulnerability.
While LexisNexis has not disclosed the nature of the "unusual activity" or whether data was compromised, the incident follows two prior breaches this year. In January, attackers exploited the React2Shell vulnerability to access legacy data from LexisNexis’ Legal & Professional division, and in April 2023, a breach at its Risk Solutions arm exposed data on approximately 360,000 individuals. The company is working with a cybersecurity forensic firm to investigate and remediate the latest incident.
LexisNexis TPRM report: https://www.rankiteo.com/company/lexisnexis
Third-party vendor TPRM report: https://www.rankiteo.com/company/venminder
"id": "venlex1786448387",
"linkid": "venminder, lexisnexis",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Customers paying tens of '
'thousands annually for services',
'industry': 'Legal, Compliance, and Risk Solutions',
'name': 'LexisNexis',
'type': 'Corporation'}],
'customer_advisories': 'Internal communication regarding outages and '
'restoration timeline',
'description': 'LexisNexis temporarily disabled its Diligence, Metabase API, '
"and Newsdesk services after detecting 'unusual activity' on "
'servers managed by a third-party vendor. The company '
'proactively disconnected the affected systems to contain the '
'issue and protect customer data while an investigation '
'continues.',
'impact': {'customer_complaints': 'Customers planning to seek compensation',
'downtime': 'Wednesday through the weekend (partial restoration '
'over the weekend)',
'operational_impact': 'Services disabled, outages affecting '
'customer operations',
'systems_affected': 'Diligence, Metabase API, Newsdesk'},
'investigation_status': 'Ongoing',
'references': [{'source': 'The Register'}],
'response': {'communication_strategy': 'Internal communication to customers',
'containment_measures': 'Proactively disconnected affected '
'systems',
'incident_response_plan_activated': 'Yes',
'recovery_measures': 'Partial restoration of Diligence, '
'progressive restoration of Newsdesk and '
'Metabase API',
'remediation_measures': 'Investigation and testing before '
'restoration',
'third_party_assistance': 'Cybersecurity forensic firm'},
'title': 'LexisNexis Takes Key Services Offline Following Third-Party Server '
'Incident',
'type': 'Third-party breach'}