LexisNexis Takes Key Services Offline Amid Suspicious Server Activity

LexisNexis takes its Diligence, Metabase API, and Newsdesk services offline after detecting unusual activity on servers managed by an unnamed third-party vendor. The company disconnects from the vendor's systems immediately to protect customers and contain the issue at its source. LexisNexis confirms it is investigating the incident with help from a cybersecurity forensic firm and plans to rebuild affected systems in a new environment before restoring service.

The impacted products serve a broad range of professionals across corporations, law firms, financial institutions, and government agencies. Nexis Diligence functions as a due diligence and risk research platform for compliance teams, while the Metabase API delivers news and media data feeds for enterprise integration. Newsdesk provides media monitoring and analytics primarily for communications and public relations teams.

Some observers speculate about a possible connection to a recent zero-day SQL injection vulnerability affecting the Metabase Cloud platform, but LexisNexis president Todd Larsen explicitly denies any link. He clarifies that Nexis Solutions does not use Metabase Cloud services and that the Nexis Metabase API product has no relationship to Metabase Cloud or its reported vulnerability. This incident follows a separate 2025 breach in which hackers stole personal data of 364,000 individuals through LexisNexis private GitHub repositories.

Read More at the original source →