Skip to main content
Back to overview
Medium

LexisNexis Legal & Professional data breach by FulcrumSec

LexisNexis has confirmed a data breach after hackers leaked data allegedly stolen from its systems, but the legal and risk solutions giant claims the impact is limited.

Key points

  • LexisNexis has confirmed a data breach after hackers leaked data allegedly stolen from its systems, but the legal and risk solutions giant claims the impact is limited. The hackers announced the intrusion on a cybercrime forum on Tuesday. Based on th
  • LexisNexis Legal & Professional data breach by FulcrumSec

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Mar 11, 2026
Updated
Aug 5, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking, Error activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

LexisnexisData DisclosureLexisNexis LegalProfessionalFulcrumSec LexisNexisTuesday. BasedLexisNexisRepresentatives of LexisNexis LegalSecurityWeekIDs

Quick context

Questions about this signal

What happened in this signal?

LexisNexis has confirmed a data breach after hackers leaked data allegedly stolen from its systems, but the legal and risk solutions giant claims the impact is limited.  The hackers announced the intrusion on a cybercrime forum on Tuesday. Based on their statement, they attempted to extort LexisNexis but were unsuccessful.  Representatives of LexisNexis Legal & Professional said in a statement to SecurityWeek that while the attackers did gain access to some servers, the compromised systems mostly stored legacy and deprecated data from prior to 2020. The company has confirmed that information such as customer names, user IDs, business contact details, the IPs of customer survey respondents, and support tickets was compromised.  “LexisNexis Legal & Professional has investigated a security matter and based on the investigation and testing we have done to date, we believe the matter is contained,” the company said. “We have no evidence of compromise of or impact to our products and services.” It added, “The impacted information did not contain Social Security numbers, driver’s license numbers, or any other sensitive personally identifiable information; credit card, bank accounts, or any other financial information; active passwords; or customer search queries, customer client or matter information, or customer contracts.” Advertisement. Scroll to continue reading. The hackers suggested that they exploited the React2Shell vulnerability and improperly secured AWS instances to access and exfiltrate more than 2GB of data. The cyberattack allegedly took place last week. The threat actor claimed to have obtained millions of data records, including enterprise account data, employee credentials, software development secrets, and personal information on 400,000 people, including over 100 individuals with .gov email addresses. The compromised personal information includes names, phone numbers, email addresses, and job roles. This is not the first data breach LexisNexis has suffered in recent years. LexisNexis Risk Solutions last year confirmed that a 2024 intrusion at a third party resulted in the information of more than 360,000 people being stolen .  *updated with additional information from LexisNexis Related : Madison Square Garden Data Breach Confirmed Months After Hacker Attack Related : 1.2 Million Affected by University of Hawaii Cancer Center Data Breach Related : Canadian Tire Data Breach Impacts 38 Million Accounts Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

When was this signal reported?

Shadow Tier lists Mar 11, 2026 as the signal date.

Which organization is connected to this signal?

Lexisnexis is the organization connected to this public signal.

Explore Lexisnexis
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence