LexisNexis shut down Nexis Diligence, Nexis Metabase API, and Nexis Newsdesk after detecting suspicious activity on servers hosted and managed by an unnamed third-party vendor. The company said it disconnected from the affected vendor systems to contain the incident and protect customers, and has brought in a cybersecurity forensic firm to investigate while rebuilding impacted systems in a new environment before restoring service.
LexisNexis said the Nexis Metabase API is not connected to Metabase Cloud and is unrelated to the recently disclosed Metabase SQL injection zero-day. The outage follows earlier LexisNexis security incidents reported in 2025, including a breach affecting more than 364,000 individuals tied to exposed private GitHub repositories and a separate compromise of AWS-hosted infrastructure in which stolen files were later leaked.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
In May 2025, LexisNexis disclosed a cybersecurity incident involving unauthorized access to its private GitHub repositories. The theft exposed personal data belonging to about 364,000 individuals.
LexisNexis previously confirmed that a limited number of servers were accessed without authorization during the March 2025 incident. The company said those servers contained mostly legacy data.
In March 2025, LexisNexis was targeted in an attack attributed to FulcrumSec, which exploited the React2Shell flaw in the company's AWS infrastructure. The attackers stole private files and later leaked them.
Following the shutdown, LexisNexis said it was investigating the incident with help from a cybersecurity forensic firm and rebuilding affected systems in a new environment before restoring service. The company also stated that Nexis Metabase API is unrelated to Metabase Cloud and its recently disclosed zero-day.
Earlier in the week of the reports, LexisNexis detected unusual activity on servers hosted and managed by an unnamed third-party vendor and took Nexis Diligence, Nexis Metabase API, and Nexis Newsdesk offline. The company disconnected from the affected systems to contain the issue and protect customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
dysruptionhub.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.