LexisNexis Pulls Three Services Offline After Vendor Server Break-In

The data analytics giant disconnected Nexis Diligence, Metabase API and Newsdesk after spotting suspicious activity on a third party's servers, and is rebuilding the systems from scratch.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A data center with servers being physically disconnected from network cables by technicians in gloves, server racks powered down in sequence, documentation and
Share

Key points

  • LexisNexis took Nexis Diligence, Nexis Metabase API and Nexis Newsdesk offline last week after spotting unusual activity on servers run by an unnamed third-party vendor.
  • The company is rebuilding the affected systems in a new environment and has hired an outside forensic firm to investigate.
  • Nexis Solutions president Todd Larsen confirmed the shutdown and said the incident is unrelated to a separate zero-day flaw disclosed by the Metabase analytics platform.
  • LexisNexis disclosed a breach in May 2025 that exposed personal data on 364,000 people through its private GitHub repositories.
  • A group calling itself FulcrumSec hit the company in March 2025 by exploiting a flaw in its Amazon Web Services setup.

LexisNexis yanked three Nexis-branded products off the internet after finding what it calls "unusual activity" on servers run by an outside supplier. The move, first reported by BleepingComputer, took Nexis Diligence, the Nexis Metabase API and Nexis Newsdesk offline while investigators work out what happened. The vendor's name has not been disclosed.

In a note to customers last week, LexisNexis said it spotted the activity earlier that week and cut the connection immediately. "To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems," the notice read.

Rather than restart the same servers, the company is rebuilding the services in a fresh environment before switching them back on. A cybersecurity forensic firm is helping with the review.

What are the affected services?

All three products serve business customers. Nexis Diligence is used by compliance staff to run background checks on companies and people. The Nexis Metabase API pipes news and media data into other firms' software. Nexis Newsdesk is a media-monitoring dashboard used by communications and marketing teams to track coverage.

LexisNexis sells legal, regulatory and risk research to law firms, banks, corporations and government agencies.

Is this connected to the Metabase zero-day?

No, according to the company. Confusion arose because the separate Metabase analytics platform disclosed last Thursday that its Cloud hosting service had been hit in a data-theft attack using a critical zero-day SQL injection flaw. A zero-day is a software bug the maker didn't know about; SQL injection lets attackers pull data from a database by feeding it rigged commands. We covered that Metabase incident on 7 August 2026, when the same flaw was linked to breaches at Framework and Tally.

Todd Larsen, president of Nexis Solutions, told BleepingComputer the two incidents aren't linked. "Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability," he said. The shared name is coincidence.

Should customers be worried about their data?

Too early to say. LexisNexis hasn't confirmed whether any customer data was accessed or copied, only that suspicious activity was seen and services were pulled as a precaution. No timeline for restoring the products has been published.

Users of the three services should expect continued downtime and watch for a follow-up notice on whether their data was touched.

Recent history

This is the third security incident LexisNexis has publicly dealt with in 2025.

Date Incident Impact
March 2025 FulcrumSec exploited a React2Shell flaw in the company's AWS setup Files stolen and later leaked; LexisNexis said mostly legacy data
May 2025 Attackers reached private GitHub code repositories Personal data on 364,000 people exposed
November 2025 Unusual activity on third-party vendor servers Nexis Diligence, Metabase API and Newsdesk taken offline

A supplier's servers, a code repository, a cloud misconfiguration: the pattern points less at any single weak spot and more at the sprawl of systems a company this size has to defend. It's a pattern we've tracked across the industry this year. How attackers got onto the vendor's servers in the current incident still hasn't been disclosed, and that gap matters most right now.

© 2026 Threat Vectr