LexisNexis Services Offline Due to Suspicious Third-Party Server Activity

LexisNexis Services Offline Due to Suspicious Third-Party Server Activity

First seen 10 Aug 2026, 14:36 UTC Bleepingcomputerwww.wiz.io 98% similarity 68.0

Article Content

Browse articles
ThreatCluster

LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline following unusual activity detected on servers managed by an unnamed third-party vendor. The company is currently investigating the incident with a cybersecurity forensic firm and is in the process of rebuilding affected systems. A notification sent to customers indicated that the decision to disconnect from the third-party systems was made to protect customer data. Last Thursday, it was reported that the Metabase Cloud hosting service was targeted in data-theft attacks exploiting a critical zero-day SQL injection vulnerability. Todd Larsen, president of LexisNexis Solutions, confirmed that their services are not connected to the Metabase Cloud services. This incident follows previous breaches at LexisNexis, including a May 2025 incident where hackers stole personal data from 364,000 individuals. The company had also faced a breach in March 2026 involving the threat actor 'FulcrumSec.'

Key Points: • LexisNexis services were taken offline due to suspicious activity on third-party servers. • The Metabase Cloud service was targeted in data-theft attacks exploiting a zero-day vulnerability. • LexisNexis has a history of cybersecurity incidents, including significant data breaches in 2025 and 2026.

ThreatCluster AI How this analysis works

Timeline

2025-05-01
LexisNexis data breach disclosed
Hackers stole personal data of 364,000 individuals after unauthorized access to private GitHub repositories.
BleepingComputer
2026-03-01
FulcrumSec targets LexisNexis
The threat actor exploited the 'React2Shell' flaw in LexisNexis' AWS infrastructure to steal and leak private files.
BleepingComputer
2026-08-03
Metabase Cloud service targeted
Data-theft attacks leveraging a critical zero-day SQL injection vulnerability were reported against the Metabase Cloud hosting service.
BleepingComputer
2026-08-10
LexisNexis services taken offline
The Diligence, Metabase API, and Newsdesk services were shut down due to unusual activity on third-party vendor servers.
BleepingComputer

Community

Browse all →