LexisNexis Pulls Three Services Offline After Vendor Server Break-In

The data analytics giant disconnected Nexis Diligence, Metabase API and Newsdesk after spotting suspicious activity on a third party's servers, and is rebuilding the systems from scratch.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial shot of a modern glass office tower at dusk with cold blue interior lighting on empty open-plan floors, a faint reflection of code-like patt
Share

Key points

  • LexisNexis took Nexis Diligence, Nexis Metabase API and Nexis Newsdesk offline last week after spotting unusual activity on servers run by an unnamed third-party vendor.
  • The company is rebuilding the affected systems in a new environment and has hired an outside forensic firm to investigate.
  • Nexis Solutions president Todd Larsen confirmed the shutdown but said the incident is unrelated to a separate zero-day flaw disclosed by the Metabase analytics product.
  • LexisNexis disclosed a breach in May 2025 that exposed personal data on 364,000 people through its private GitHub repositories.
  • A group calling itself FulcrumSec hit the company earlier in 2025 by exploiting a flaw in its Amazon Web Services setup.

LexisNexis has yanked three of its Nexis-branded products off the internet after finding what it calls "unusual activity" on servers run by an outside supplier. The move, first reported by BleepingComputer, took Nexis Diligence, the Nexis Metabase API and Nexis Newsdesk offline while investigators figure out what happened.

The company is not naming the vendor.

In a note to customers last week, LexisNexis said it spotted the activity earlier that week and cut the connection immediately. "To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems," the notice read.

Rather than restart the same servers, LexisNexis is rebuilding the services in a fresh environment before switching them back on. A cybersecurity forensic firm is helping with the review.

What are the affected services?

The three products are business tools, not consumer ones. Nexis Diligence is used by compliance staff to run background checks on companies and people. The Nexis Metabase API pipes news and media data into other firms' software. Nexis Newsdesk is a media-monitoring dashboard used by press and marketing teams to track coverage.

LexisNexis itself is a large data analytics company selling legal, regulatory and risk research to law firms, banks, corporations and government agencies.

Is this connected to the Metabase zero-day?

No, according to the company. Confusion arose because the separate Metabase analytics platform disclosed last Thursday that its Cloud hosting service had been hit with a data-theft attack using a critical zero-day SQL injection flaw (a zero-day is a software bug the maker did not know about, and SQL injection is a trick that lets attackers pull data straight out of a database by feeding it rigged commands).

Todd Larsen, president of Nexis Solutions at LexisNexis, told reporters the two are not linked. "Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability," Larsen said. The shared name is coincidence.

Should customers be worried about their data?

Too early to say. LexisNexis has not confirmed whether any customer data was accessed or copied, only that suspicious activity was seen and services were pulled as a precaution. The company has not published a timeline for restoring the products.

Business users of the three services should expect continued downtime and watch for a follow-up notice from LexisNexis on whether any of their data was touched.

Recent history

This is the third security incident LexisNexis has publicly dealt with in 2025.

Date Incident Impact
March 2025 FulcrumSec exploited a React2Shell flaw in the company's AWS setup Files stolen and later leaked; LexisNexis said mostly legacy data
May 2025 Attackers reached private GitHub code repositories Personal data on 364,000 people exposed
November 2025 Unusual activity on third-party vendor servers Nexis Diligence, Metabase API and Newsdesk taken offline

The pattern (a supplier here, a code repo there, a cloud misconfiguration before that) points less at any single weak spot and more at the sprawl of systems a company like LexisNexis has to defend. The details of the current incident, including how the attackers got onto the vendor's servers, have not been disclosed.

© 2026 Threat Vectr