
LexisNexis has taken three of its Nexis business services offline after spotting suspicious activity on servers hosted and managed by an unnamed third-party vendor. The affected services are Nexis Diligence (a due-diligence and risk research platform used by compliance professionals), Nexis Metabase API (news and media data feeds used in enterprise systems), and Nexis Newsdesk (a media monitoring and analytics service for communications and PR teams). The company says it is working with a cybersecurity forensic firm on investigation and remediation, and that it is rebuilding the affected systems in a new environment before bringing them back online.
LexisNexis is a global data analytics company whose services are routinely used by law firms, corporations, financial institutions, government agencies, and researchers to access legal, business, regulatory, and risk information. Todd Larsen, president of the global Nexis Solutions division, confirmed the shutdown to BleepingComputer and clarified that the outage has no connection to last week’s Metabase Cloud zero-day SQL-injection breach — LexisNexis’s Nexis Metabase API product is a separately named, unrelated platform and was not running Metabase Cloud software. The incident comes after a May 2025 breach in which attackers stole personal data for 364,000 people via the company’s private GitHub repositories, and a March 2026 incident in which the threat actor “FulcrumSec” exploited an AWS flaw to steal and leak files.
