Breaking
SecurityDeveloping Story

LexisNexis disconnects vendor systems after anomaly

LexisNexis took Diligence, Metabase API, and Newsdesk offline after detecting unusual activity on third-party servers.

··5 hours ago·3 min read
Yellow and green cables are neatly connected.
Photo by Albert Stoynov on Unsplash

LexisNexis has pulled three of its services offline after spotting unusual activity on servers that a third-party vendor hosts and manages. The company says it is working with a cybersecurity forensic firm to investigate, and it is rebuilding the affected systems in a new environment before bringing them back.

Services taken down as precaution

The affected services are Nexis Diligence, Nexis Metabase API, and Nexis Newsdesk. These platforms serve different audiences: Diligence supports compliance professionals with due diligence and risk research, Metabase API offers news and media data feeds for enterprise integration, and Newsdesk provides media monitoring and analytics for communications and marketing teams.

The decision to disconnect came after the company identified unusual activity on servers managed by an unnamed third-party vendor. LexisNexis said it made the immediate call to disconnect from those third-party systems to protect customers and contain the issue at its source.

“Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week. “To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems.”

Todd Larsen, president of the global Nexis Solutions division of LexisNexis, confirmed to BleepingComputer that the services were taken down due to suspicious activity on vendor servers.

“Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation,” Larsen stated.

Investigation and rebuilding process

LexisNexis said it is investigating the incident with help from a cybersecurity forensic firm. According to the company, the affected systems are being rebuilt in a new environment before the services are restored. The notification did not specify when the services would be back online, nor did it mention any evidence of data theft.

Separate Metabase incident clarified

Last Thursday, the Metabase business intelligence and data analytics platform announced that its Cloud hosting service had been targeted in data-theft attacks leveraging a critical zero-day SQL injection vulnerability. Because of the name similarity, some observers could have assumed a connection to LexisNexis's Nexis Metabase API product, but Larsen clarified that Nexis Solutions is not a Metabase Cloud customer, and the API product has no connection to the reported vulnerability.

Recent security history

This is not the first time LexisNexis has dealt with a security incident. In May 2025, the company disclosed that hackers stole the personal data of 364,000 individuals after gaining unauthorized access to its private GitHub repositories. Earlier that year, in March, the threat actor FulcrumSec targeted LexisNexis by exploiting the React2Shell flaw in the company's AWS infrastructure to steal and later leak private files. At the time, LexisNexis confirmed unauthorized access to “a limited number of servers,” noting that they contained mostly legacy data.

The current incident appears to involve a different set of circumstances, but the company has not provided details beyond the unusual activity on vendor servers.

What to watch

The key facts so far: three services are down, customers were notified last week, and the company is rebuilding systems in a new environment. The investigation is ongoing, and LexisNexis has not said whether any customer data was accessed or exfiltrated.

For businesses that rely on these platforms for due diligence, media monitoring, or data feeds, the outage itself is the immediate impact. The longer the services remain offline, the more it may affect compliance workflows and research operations.

The company's decision to rebuild in a new environment suggests a cautious approach, but without further details, the scope of the problem remains unclear. As the forensic review continues, the situation may evolve, and customers should watch for updates from LexisNexis.

Why it matters

This incident underscores the potential risks of third-party vendor arrangements, even for a company with LexisNexis's scale. The fact that the company acted swiftly to disconnect services and is rebuilding in a new environment suggests it is taking the matter seriously, but it also highlights that supply chain dependencies can introduce vulnerabilities that are hard to detect.

Customers affected by the outage should consider contingency plans and stay in touch with LexisNexis for status updates. The incident may also prompt other organizations to review their own vendor management practices, especially when those vendors handle sensitive data.

#lexisnexis#data-breach#third-party-vendor#service-outage#cybersecurity

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories