LexisNexis shuts down services after suspicious activity on servers

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor.

The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online.

“Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week.

“To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems.”

LexisNexis is a global data analytics company providing legal, business, regulatory, and risk information research, public records, and risk management services. Its services are widely used by corporations, law firms, financial institutions, government agencies, consultants, and researchers.

Nexis Diligence is a due diligence and risk research platform used by compliance professionals, while Nexis Metabase API provides news and media data feeds for integration into enterprise systems.

The Nexis Newsdesk media monitoring and analytics service is used primarily by communications, public relations, and marketing teams.

Todd Larsen, the president of the global Nexis Solutions division of LexisNexis, confirmed to BleepingComputer that the services were taken down due to suspicious activity on vendor servers.

“Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation,” Larsen stated.

Last Thursday, the Metabase business intelligence and data analytics platform announced that its Cloud hosting service had been targeted in data-theft attacks leveraging a critical zero-day SQL injection vulnerability.

In a clarification for BleepingComputer, Larsen says that Lexis Solutions does not use Metabase Cloud services.

“Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability,” Larsen told BleepingComputer.

In May 2025, LexisNexis disclosed a cybersecurity incident in which hackers stole the personal data of 364,000 individuals after gaining unauthorized access to its private GitHub repositories.

Earlier this year in March, LexisNexis was targeted by the threat actor ‘FulcrumSec’ after exploiting the ‘React2Shell’ flaw in the company’s AWS infrastructure to steal and later leak private files.

At the time, the company confirmed unauthorized access to “a limited number of servers,” underlining that they contained mostly legacy data.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Metabase SQLi zero-day exploited in customer data-theft attacks

Real emails, hijacked payments: Two H1 2026 attack chains

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

Train for all eight CISSP domains from home for just $20

How AI-powered phishing killed blocklists for good

Metabase SQLi zero-day exploited in customer data-theft attacks

Levi Strauss & Co. says hackers stole corporate data in cyberattack

North Carolina Ports confirms cyberattack disrupting operations

Webinar: Shadow AI in 2026 (and how attackers are taking advantage)

Spend four hours inside a fully-simulated underground with DARKROOM.

AI is a data-breach time bomb: Read the new report

See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.

See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.