V-Help
← All news
Security

LexisNexis Suspends Services Amid Suspicious Server Activity

LexisNexis Suspends Services Amid Suspicious Server Activity

Photo: BleepingComputer

Quick answer

LexisNexis suspended its Diligence, Metabase API, and Newsdesk services after detecting suspicious activity on third-party servers.

LexisNexis, a data analytics provider serving legal, financial, and government organizations, announced the temporary shutdown of several services. The affected platforms—Diligence, Metabase API, and Newsdesk—were disconnected after suspicious activity was detected on servers managed by a third-party vendor.

According to the company, the incident was identified earlier this week. To mitigate potential risks and contain the threat, LexisNexis made an immediate decision to disconnect the affected systems. The investigation is now underway with the involvement of a leading cybersecurity firm, while the affected services are being restored in a new environment.

Todd Larsen, head of Nexis Solutions, confirmed that the incident is not linked to the Metabase Cloud platform, which was previously targeted in zero-day vulnerability attacks. LexisNexis emphasized that it does not use Metabase’s cloud services, and the incident does not impact this platform.

Notably, in May 2025, the company faced a data breach when threat actors gained access to private GitHub repositories and stole personal data of 364,000 individuals. Earlier this year, in March, LexisNexis was also targeted by the FulcrumSec group, which exploited a vulnerability in AWS infrastructure to steal data.

Common questions

Which LexisNexis services were affected by the outage?
The company temporarily suspended Diligence, Metabase API, and Newsdesk services due to suspicious activity on third-party servers.
Is the incident related to the Metabase Cloud vulnerability?
No, LexisNexis confirmed it does not use Metabase Cloud, and the incident is unrelated to this platform or its vulnerabilities.
What steps is LexisNexis taking to resolve the issue?
The company is working with cybersecurity experts to investigate the incident and is restoring affected systems in a new environment before resuming service operations.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer