Skip to main content
Back to overview
Medium

LexisNexis Risk Solutions Discloses Data Breach Affecting 364,000 Individuals

Data broker giant LexisNexis Risk Solutions (LNRS) is notifying more than 364,000 people that their personal information was stolen in a December 2024 data breach.

Key points

  • LexisNexis Risk Solutions (LNRS) affected.
  • 364,000 individuals impacted.
  • Personal information stolen from a third-party platform (GitHub account).

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
May 28, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking, Error activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

LexisnexisData DisclosureLexisNexis Risk SolutionsLNRSMaine Attorney GeneralOfficePersonalMaine AGOAdvertisement. ScrollResponding

Quick context

Questions about this signal

What happened in this signal?

Data broker giant LexisNexis Risk Solutions (LNRS) is notifying more than 364,000 people that their personal information was stolen in a December 2024 data breach. The incident occurred on December 25, but LNRS learned of it on April 1, 2025, the company said in the notification letter to the impacted individuals, a copy of which was submitted to the Maine Attorney General’s Office. “An unauthorized third party acquired certain LNRS data from a third-party platform used for software development. The issue did not affect LNRS’s own networks or systems,” the company said. Personal information stolen in the attack, LNRS says, includes names, dates of birth, phone numbers, email addresses, Social Security numbers, and driver’s license number. “No financial or credit card information was affected. We have no evidence that your data has been further misused,” the company says, noting that it has notified the relevant authorities of the incident. LNRS informed the Maine AGO that 364,333 individuals were affected by the data breach and that it is providing them with two years of free identity protection and credit monitoring services. Advertisement. Scroll to continue reading. Responding to a SecurityWeek inquiry, LNRS said that it learned of the data breach after it “received a report from an unknown third party claiming to have accessed certain information belonging to LNRS.” The threat actor had accessed the company’s GitHub account and accessed “some software artifacts as well as some personal information.” “There was no compromise of our own systems, infrastructure, or products. We are notifying approximately 360,000 individuals and appropriate regulators. We have also reported this incident to law enforcement,” LNRS said. Based in Atlanta, Georgia, LexisNexis Risk Solutions collects user information from public records and other sources and provides it to financial, insurance, healthcare, and government organizations, to help them identify risks and fraud. Related: Marlboro-Chesterfield Pathology Data Breach Impacts 235,000 People Related: Coinbase Says Rogue Contractor Data Breach Affects 69,461 Users Related: UK Legal Aid Agency Finds Data Breach Following Cyberattack Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

When was this signal reported?

Shadow Tier lists May 28, 2025 as the signal date.

Which organization is connected to this signal?

Lexisnexis is the organization connected to this public signal.

Explore Lexisnexis
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence