LexisNexis Legal & Professional confirmed that an unauthorized party accessed a limited number of its servers after a threat actor using the alias FulcrumSec leaked roughly 2 GB of allegedly stolen files on underground forums. LexisNexis stated the exposed information was mostly legacy/deprecated data from prior to 2020 (e.g., customer names, user IDs, business contact details, products used, customer survey data including respondent IP addresses, and support tickets) and said it found no evidence of impact to products or services; the company reported the matter to law enforcement and engaged an external forensics firm.
FulcrumSec claimed the intrusion began by exploiting the React2Shell vulnerability in an unpatched React frontend application to gain access to LexisNexis’ AWS environment, and alleged broader access within cloud resources (including an ECS task role and data stores) and the presence of government-related accounts (e.g., .gov email addresses) in the stolen dataset. Public reporting notes a discrepancy between the actor’s claims (e.g., “millions of records,” passwords, and other internal artifacts) and LexisNexis’ characterization of the exposed data as limited and non-sensitive (no SSNs, financial data, active passwords, or customer search queries), but multiple outlets corroborated that the leaked files are tied to a real, now-contained incident affecting LexisNexis’ Legal & Professional division.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
LexisNexis Legal & Professional confirmed that attackers accessed a limited number of servers containing mostly legacy or deprecated pre-2020 data and said the incident had been contained with no evidence of impact to products or services. The company said it engaged an external forensics firm, notified law enforcement, and informed affected current and former customers, while stating that highly sensitive data such as Social Security numbers, financial data, and active passwords were not exposed.
After the intrusion, FulcrumSec publicly posted or advertised roughly 2 GB of purported LexisNexis data on cybercrime forums, claiming the dump contained millions of records, including customer and business information. The leak prompted public scrutiny and media reporting about the scope of the alleged compromise.
Multiple reports say the threat actor FulcrumSec claimed initial access to LexisNexis Legal & Professional on February 24, 2026 by exploiting an unpatched React frontend application, leading to access to the company's AWS environment. The actor alleged it could reach Redshift, VPC databases, Secrets Manager, and other cloud assets and exfiltrate about 2.04 GB of data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.