Back to Feed
BreachesAug 10, 2026

LexisNexis shuts down services after suspicious activity on servers

LexisNexis takes down Diligence, Metabase API, and Newsdesk services due to suspicious activity on vendor servers.

Summary

LexisNexis has taken down its Diligence, Metabase API, and Newsdesk services after identifying suspicious activity on servers managed by a third-party vendor. The company is investigating the incident with a cybersecurity firm and rebuilding affected systems. This follows previous security incidents involving LexisNexis in May 2025 and March of this year.

Full text

LexisNexis shuts down services after suspicious activity on servers By Bill Toulas August 10, 2026 08:11 AM 0 LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online. “Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week. “To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems.” Service outage alertSource: BleepingComputer LexisNexis is a global data analytics company providing legal, business, regulatory, and risk information research, public records, and risk management services. Its services are widely used by corporations, law firms, financial institutions, government agencies, consultants, and researchers. Nexis Diligence is a due diligence and risk research platform used by compliance professionals, while Nexis Metabase API provides news and media data feeds for integration into enterprise systems. The Nexis Newsdesk media monitoring and analytics service is used primarily by communications, public relations, and marketing teams. Todd Larsen, the president of the global Nexis Solutions division of LexisNexis, confirmed to BleepingComputer that the services were taken down due to suspicious activity on vendor servers. “Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation,” Larsen stated. Last Thursday, the Metabase business intelligence and data analytics platform announced that its Cloud hosting service had been targeted in data-theft attacks leveraging a critical zero-day SQL injection vulnerability. In a clarification for BleepingComputer, Larsen says that Lexis Solutions does not use Metabase Cloud services. "Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability," Larsen told BleepingComputer. In May 2025, LexisNexis disclosed a cybersecurity incident in which hackers stole the personal data of 364,000 individuals after gaining unauthorized access to its private GitHub repositories. Earlier this year in March, LexisNexis was targeted by the threat actor ‘FulcrumSec’ after exploiting the ‘React2Shell’ flaw in the company's AWS infrastructure to steal and later leak private files. At the time, the company confirmed unauthorized access to “a limited number of servers,” underlining that they contained mostly legacy data. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: Metabase SQLi zero-day exploited in customer data-theft attacksReal emails, hijacked payments: Two H1 2026 attack chains How AI Exposed a Browser Security Gap that Enterprises Cannot IgnoreTrain for all eight CISSP domains from home for just $20How AI-powered phishing killed blocklists for good

Entities

Diligence (product)Metabase API (product)Newsdesk (product)LexisNexis (vendor)FulcrumSec (threat_actor)