Bleepingcomputer
LexisNexis Services Offline Due to Suspicious Third-Party Server Activity
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline following unusual activity detected on servers managed by an unnamed third-party vendor. The company is currently investigating the incident with a cybersecurity forensic firm and is in the process of rebuilding affected systems. A notification sent to customers indicated that the decision to disconnect from the third-party systems was made to protect customer data. Last Thursday, it was reported that the Metabase Cloud hosting service was targeted in data-theft attacks exploiting a critical zero-day SQL injection vulnerability. Todd Larsen, president of LexisNexis Solutions, confirmed that their services are not connected to the Metabase Cloud services. This incident follows previous breaches at LexisNexis, including a May 2025 incident where hackers stole personal data from 364,000 individuals. The company had also faced a breach in March 2026 involving the threat actor 'FulcrumSec.'
Key Points: • LexisNexis services were taken offline due to suspicious activity on third-party servers. • The Metabase Cloud service was targeted in data-theft attacks exploiting a zero-day vulnerability. • LexisNexis has a history of cybersecurity incidents, including significant data breaches in 2025 and 2026.