LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor.

The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online.

“Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week.

“To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems.”

LexisNexis is a global data analytics company providing legal, business, regulatory, and risk information research, public records, and risk management services. Its services are widely used by corporations, law firms, financial institutions, government agencies, consultants, and researchers.

Nexis Diligence is a due diligence and risk research platform used by compliance professionals, while Nexis Metabase API provides news and media data feeds for integration into enterprise systems.

The Nexis Newsdesk media monitoring and analytics service is used primarily by communications, public relations, and marketing teams.

Todd Larsen, the president of the global Nexis Solutions division of LexisNexis, confirmed to BleepingComputer that the services were taken down due to suspicious activity on vendor servers.

“Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation,” Larsen stated.

Last Thursday, the Metabase business intelligence and data analytics platform announced that its Cloud hosting service had been targeted in data-theft attacks leveraging a critical zero-day SQL injection vulnerability.

In a clarification for BleepingComputer, Larsen says that Lexis Solutions does not use Metabase Cloud services.

"Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability," Larsen told BleepingComputer.

In May 2025, LexisNexis disclosed a cybersecurity incident in which hackers stole the personal data of 364,000 individuals after gaining unauthorized access to its private GitHub repositories.

Earlier this year in March, LexisNexis was targeted by the threat actor ‘FulcrumSec’ after exploiting the ‘React2Shell’ flaw in the company's AWS infrastructure to steal and later leak private files.

At the time, the company confirmed unauthorized access to “a limited number of servers,” underlining that they contained mostly legacy data.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper