LexisNexis takes three services offline after suspicious activity on vendor servers
This digest was compiled by AI from multiple sources — links to the originals are below.

LexisNexis takes its Diligence, Metabase API, and Newsdesk services offline following unusual activity on servers managed by a third-party vendor, the company confirmed last week. The company is investigating with a cybersecurity forensic firm and rebuilding affected systems in a new environment.
The Suspicious Activity
LexisNexis notified customers last week that it identified unusual activity on servers hosted and managed by an unnamed third-party vendor. To protect customers, the company immediately disconnected from those systems, taking Diligence, Metabase API, and Newsdesk offline. Todd Larsen, president of global Nexis Solutions, confirmed the action and said a cybersecurity forensic firm is assisting with investigation and remediation. The affected services are used by corporations, law firms, and government agencies for due diligence, media monitoring, and data feeds.
Previous Cybersecurity Incidents
In May 2025, LexisNexis disclosed a breach in which hackers stole personal data of 364,000 individuals after accessing private GitHub repositories. In March 2026, the threat actor FulcrumSec exploited a flaw in the company's AWS infrastructure to steal and leak private files; the company confirmed unauthorized access to servers containing mostly legacy data. Larsen clarified that Nexis Solutions is not a Metabase Cloud customer and the Nexis Metabase API has no connection to the recent Metabase Cloud zero-day attacks.
What's Next
LexisNexis has not provided a timeline for when the services will be restored. It remains unclear whether customer data was compromised in the latest incident.
2 sources
LexisNexis takes three services offline after suspicious activity on vendor servers



