LexisNexis Shuts Down Services Amid Suspicious Activity on Third-Party Servers
Global data analytics company LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline as a precautionary measure after detecting unusual activity on servers hosted by an unnamed third-party vendor. The move is part of the company’s response to the incident, which includes investigating the matter with the assistance of a cybersecurity forensic firm and rebuilding affected systems in a new environment before bringing them back online.
LexisNexis provides legal, business, regulatory, and risk information research services to corporations, law firms, financial institutions, government agencies, consultants, and researchers. Its Diligence platform is used for due diligence and risk research by compliance professionals, while the Metabase API offers news and media data feeds for integration into enterprise systems. The Newsdesk service is primarily utilized by communications, public relations, and marketing teams.
According to Todd Larsen, president of the global Nexis Solutions division of LexisNexis, the services were taken down due to suspicious activity on vendor servers. “Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation,” Larsen stated. The company has not disclosed further details about the nature of the suspicious activity or whether any data breaches have occurred.
It’s worth noting that LexisNexis has faced similar security incidents in the past. In May 2025, the company disclosed a cybersecurity incident in which hackers stole the personal data of 364,000 individuals after gaining unauthorized access to its private GitHub repositories. Earlier this year, LexisNexis was targeted by the threat actor ‘FulcrumSec’ who exploited the ‘React2Shell’ flaw in the company’s AWS infrastructure to steal and later leak private files.
The incident highlights the importance of robust security measures, particularly when it comes to third-party vendors. Companies often rely on external service providers to host their data, but this can also introduce additional risks if those vendors have poor cybersecurity practices or are compromised by attackers.
As a result of this incident, LexisNexis is taking proactive steps to mitigate the risk and protect its customers’ data. The company’s decision to rebuild affected systems in a new environment before bringing them back online demonstrates a commitment to transparency and customer trust.
For security teams, this incident serves as a reminder to regularly test their defenses against potential vulnerabilities. A recent study found that 54% of successful attacks go undetected by log files and SIEM/EDR systems. Conducting breach and attack simulation tests can help identify weaknesses in these systems before attackers do.
In conclusion, LexisNexis’s decision to shut down its services amid suspicious activity on third-party servers underscores the importance of robust security measures in today’s digital landscape. As a precautionary measure, companies should regularly review their vendor relationships and ensure that they have adequate controls in place to mitigate potential risks associated with external service providers.
Source: Bleeping Computer — 2026-08-10