Skip to main content

Company intelligence

Lexisnexis cybersecurity incidents and threat signals

lexisnexis.com

Lexisnexis logo

This company page brings together public reporting currently associated with Lexisnexis. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

2

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

0

High or critical

confidence classifications

August 5, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Lexisnexis. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Lexisnexis

Lexisnexis logoRansomware
Medium

LexisNexis Legal & Professional data breach by FulcrumSec

LexisNexis has confirmed a data breach after hackers leaked data allegedly stolen from its systems, but the legal and risk solutions giant claims the impact is limited.  The hackers announced the intrusion on a cybercrime forum on Tuesday. Based on their statement, they attempted to extort LexisNexis but were unsuccessful.  Representatives of LexisNexis Legal & Professional said in a statement to SecurityWeek that while the attackers did gain access to some servers, the compromised systems mostly stored legacy and deprecated data from prior to 2020. The company has confirmed that information such as customer names, user IDs, business contact details, the IPs of customer survey respondents, and support tickets was compromised.  “LexisNexis Legal & Professional has investigated a security matter and based on the investigation and testing we have done to date, we believe the matter is contained,” the company said. “We have no evidence of compromise of or impact to our products and services.” It added, “The impacted information did not contain Social Security numbers, driver’s license numbers, or any other sensitive personally identifiable information; credit card, bank accounts, or any other financial information; active passwords; or customer search queries, customer client or matter information, or customer contracts.” Advertisement. Scroll to continue reading. The hackers suggested that they exploited the React2Shell vulnerability and improperly secured AWS instances to access and exfiltrate more than 2GB of data. The cyberattack allegedly took place last week. The threat actor claimed to have obtained millions of data records, including enterprise account data, employee credentials, software development secrets, and personal information on 400,000 people, including over 100 individuals with .gov email addresses. The compromised personal information includes names, phone numbers, email addresses, and job roles. This is not the first data breach LexisNexis has suffered in recent years. LexisNexis Risk Solutions last year confirmed that a 2024 intrusion at a third party resulted in the information of more than 360,000 people being stolen .  *updated with additional information from LexisNexis Related : Madison Square Garden Data Breach Confirmed Months After Hacker Attack Related : 1.2 Million Affected by University of Hawaii Cancer Center Data Breach Related : Canadian Tire Data Breach Impacts 38 Million Accounts Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

Lexisnexis
Lexisnexis logoRansomware
Medium

LexisNexis Risk Solutions Discloses Data Breach Affecting 364,000 Individuals

Data broker giant LexisNexis Risk Solutions (LNRS) is notifying more than 364,000 people that their personal information was stolen in a December 2024 data breach. The incident occurred on December 25, but LNRS learned of it on April 1, 2025, the company said in the notification letter to the impacted individuals, a copy of which was submitted to the Maine Attorney General’s Office. “An unauthorized third party acquired certain LNRS data from a third-party platform used for software development. The issue did not affect LNRS’s own networks or systems,” the company said. Personal information stolen in the attack, LNRS says, includes names, dates of birth, phone numbers, email addresses, Social Security numbers, and driver’s license number. “No financial or credit card information was affected. We have no evidence that your data has been further misused,” the company says, noting that it has notified the relevant authorities of the incident. LNRS informed the Maine AGO that 364,333 individuals were affected by the data breach and that it is providing them with two years of free identity protection and credit monitoring services. Advertisement. Scroll to continue reading. Responding to a SecurityWeek inquiry, LNRS said that it learned of the data breach after it “received a report from an unknown third party claiming to have accessed certain information belonging to LNRS.” The threat actor had accessed the company’s GitHub account and accessed “some software artifacts as well as some personal information.” “There was no compromise of our own systems, infrastructure, or products. We are notifying approximately 360,000 individuals and appropriate regulators. We have also reported this incident to law enforcement,” LNRS said. Based in Atlanta, Georgia, LexisNexis Risk Solutions collects user information from public records and other sources and provides it to financial, insurance, healthcare, and government organizations, to help them identify risks and fraud. Related: Marlboro-Chesterfield Pathology Data Breach Impacts 235,000 People Related: Coinbase Says Rogue Contractor Data Breach Affects 69,461 Users Related: UK Legal Aid Agency Finds Data Breach Following Cyberattack Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Lexisnexis

FAQ

Questions about Lexisnexis cybersecurity reporting

What does the Lexisnexis page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Lexisnexis.

Does every mention of Lexisnexis appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.