LexisNexis shuts down services after suspicious activity on servers

LexisNexis Shuts Down Services After Unusual Activity on Vendor Servers

Global data analytics company LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline as part of a response to suspicious activity detected on servers managed by an unnamed third-party vendor. The move aims to protect customers from potential security risks while the company investigates the incident with assistance from a cybersecurity forensic firm.

The company’s notification to customers reveals that unusual activity was identified earlier this week on servers hosted and managed by the third-party vendor. To mitigate the issue, LexisNexis made the decision to disconnect from those systems immediately. The services are now offline as the company rebuilds affected systems in a new environment before bringing them back online.

LexisNexis provides a wide range of services used by corporations, law firms, financial institutions, government agencies, consultants, and researchers. Its platforms include Nexis Diligence, a due diligence and risk research platform; Nexis Metabase API, which provides news and media data feeds for integration into enterprise systems; and Nexis Newsdesk, a media monitoring and analytics service used primarily by communications, public relations, and marketing teams.

According to Todd Larsen, president of the global Nexis Solutions division, the decision to take down services was made in response to suspicious activity on vendor servers. An investigation is ongoing, with LexisNexis working closely with a leading cybersecurity forensic firm to review and remediate the issue.

Interestingly, this move comes on the heels of a recent announcement by Metabase regarding data-theft attacks leveraging a critical zero-day SQL injection vulnerability. However, Larsen clarified that Lexis Solutions does not use Metabase Cloud services and that its Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability.

LexisNexis has faced security incidents in the past, including a 2025 breach where hackers stole personal data of over 364,000 individuals after gaining unauthorized access to private GitHub repositories. Additionally, earlier this year, the company was targeted by threat actor ‘FulcrumSec’ after exploiting the ‘React2Shell’ flaw in its AWS infrastructure.

This incident serves as a reminder that even large and established companies like LexisNexis are not immune to security threats. It highlights the importance of having robust security measures in place, including regular monitoring and incident response planning. As the investigation continues, customers can take this opportunity to review their own security posture and ensure they have adequate defenses in place.

In today’s complex cybersecurity landscape, it’s crucial for organizations to be vigilant and proactive in addressing potential threats. By taking a proactive approach to security, businesses can minimize the risk of data breaches and protect their sensitive information. As LexisNexis continues to investigate this incident, its customers and the broader cybersecurity community can learn valuable lessons about the importance of robust security measures and incident response planning.


Source: Bleeping Computer — 2026-08-10