2
Published signals
currently linked to this company
Company intelligence
lexisnexis.com
This company page brings together public reporting currently associated with Lexisnexis. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
2
currently linked to this company
0
recent published signals
0
recent published signals
0
confidence classifications
August 5, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Lexisnexis. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
LexisNexis has confirmed a data breach after hackers leaked data allegedly stolen from its systems, but the legal and risk solutions giant claims the impact is limited. The hackers announced the intrusion on a cybercrime forum on Tuesday. Based on their statement, they attempted to extort LexisNexis but were unsuccessful. Representatives of LexisNexis Legal & Professional said in a statement to SecurityWeek that while the attackers did gain access to some servers, the compromised systems mostly stored legacy and deprecated data from prior to 2020. The company has confirmed that information such as customer names, user IDs, business contact details, the IPs of customer survey respondents, and support tickets was compromised. “LexisNexis Legal & Professional has investigated a security matter and based on the investigation and testing we have done to date, we believe the matter is contained,” the company said. “We have no evidence of compromise of or impact to our products and services.” It added, “The impacted information did not contain Social Security numbers, driver’s license numbers, or any other sensitive personally identifiable information; credit card, bank accounts, or any other financial information; active passwords; or customer search queries, customer client or matter information, or customer contracts.” Advertisement. Scroll to continue reading. The hackers suggested that they exploited the React2Shell vulnerability and improperly secured AWS instances to access and exfiltrate more than 2GB of data. The cyberattack allegedly took place last week. The threat actor claimed to have obtained millions of data records, including enterprise account data, employee credentials, software development secrets, and personal information on 400,000 people, including over 100 individuals with .gov email addresses. The compromised personal information includes names, phone numbers, email addresses, and job roles. This is not the first data breach LexisNexis has suffered in recent years. LexisNexis Risk Solutions last year confirmed that a 2024 intrusion at a third party resulted in the information of more than 360,000 people being stolen . *updated with additional information from LexisNexis Related : Madison Square Garden Data Breach Confirmed Months After Hacker Attack Related : 1.2 Million Affected by University of Hawaii Cancer Center Data Breach Related : Canadian Tire Data Breach Impacts 38 Million Accounts Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
Data broker giant LexisNexis Risk Solutions (LNRS) is notifying more than 364,000 people that their personal information was stolen in a December 2024 data breach. The incident occurred on December 25, but LNRS learned of it on April 1, 2025, the company said in the notification letter to the impacted individuals, a copy of which was submitted to the Maine Attorney General’s Office. “An unauthorized third party acquired certain LNRS data from a third-party platform used for software development. The issue did not affect LNRS’s own networks or systems,” the company said. Personal information stolen in the attack, LNRS says, includes names, dates of birth, phone numbers, email addresses, Social Security numbers, and driver’s license number. “No financial or credit card information was affected. We have no evidence that your data has been further misused,” the company says, noting that it has notified the relevant authorities of the incident. LNRS informed the Maine AGO that 364,333 individuals were affected by the data breach and that it is providing them with two years of free identity protection and credit monitoring services. Advertisement. Scroll to continue reading. Responding to a SecurityWeek inquiry, LNRS said that it learned of the data breach after it “received a report from an unknown third party claiming to have accessed certain information belonging to LNRS.” The threat actor had accessed the company’s GitHub account and accessed “some software artifacts as well as some personal information.” “There was no compromise of our own systems, infrastructure, or products. We are notifying approximately 360,000 individuals and appropriate regulators. We have also reported this incident to law enforcement,” LNRS said. Based in Atlanta, Georgia, LexisNexis Risk Solutions collects user information from public records and other sources and provides it to financial, insurance, healthcare, and government organizations, to help them identify risks and fraud. Related: Marlboro-Chesterfield Pathology Data Breach Impacts 235,000 People Related: Coinbase Says Rogue Contractor Data Breach Affects 69,461 Users Related: UK Legal Aid Agency Finds Data Breach Following Cyberattack Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Lexisnexis.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.