LexisNexis

LexisNexis took Nexis Diligence, Nexis Metabase API and Nexis Newsdesk offline after unusual activity was identified on vendor-managed servers. Diligence returned during the August 8-9 weekend with its content catalog still rebuilding, and the other two services were expected to return August 10 after testing. No later continuing service impairment tied to this incident was found by August 30, so the incident is presumed resolved even though the exact restoration time and data impact remain unknown.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A specific application or software platform became unavailable or unusable.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
DysruptionHub assesses with high confidence that LexisNexis experienced a cyber-related service disruption involving vendor-managed servers. LexisNexis said it identified unusual activity on those servers, disconnected from the affected systems and engaged a cybersecurity forensic firm. That affected-organization wording is concrete public cyber evidence, but it does not establish unauthorized or malicious access.
The company said Nexis Metabase API was unrelated to Metabase Cloud and to the critical Metabase vulnerability disclosed Aug. 6. The available evidence does not support linking this incident to that vulnerability or to LexisNexis’ separate March 2026 security event.
The incident disrupted three customer-facing research, data-delivery and media-monitoring services: Nexis Diligence, Nexis Metabase API and Nexis Newsdesk. LexisNexis accepted the availability impact to isolate the vendor-managed environment while it investigated and rebuilt the applications.
The Register reported that Diligence returned during the Aug. 8-9 weekend, although LexisNexis was still rebuilding its full content catalog. Newsdesk and the Metabase API were expected to return progressively Aug. 10, subject to successful testing. That update documents partial recovery, not a systemwide all-clear.
LexisNexis’ customer communication supplied the first public cyber-specific characterization reproduced by reporters Aug. 10. It identified unusual activity, the third-party hosting context, the isolated applications and the rebuilding plan. External reporting did not precede that affected-organization disclosure with an independent cyber characterization, supporting OC-OD classification.
The incident is presumed resolved. Aug. 10 remains the latest supported operational-impact date: Diligence had returned with its catalog still rebuilding, and Newsdesk and the Metabase API were expected to return progressively after testing. No later continuing impairment tied to these services was found by Aug. 30. The exact completion time is not public, so this is not an affirmative all-clear.
The status does not depend on whether the security investigation remains open. Continuing investigation, remediation or disclosure questions do not establish continuing service-delivery impact.
Confidence is high that LexisNexis isolated the three services because the company documented the affected applications and its containment decision. Confidence is medium in presumed resolution because the latest evidence described imminent staged restoration and no later continuing impairment was found, but LexisNexis did not publish a final restoration notice.
Data impact remains unknown: neither LexisNexis nor the reviewed reporting established whether anyone accessed or removed information. Ransomware and threat-actor attribution remain unresolved. The separate March 2026 FulcrumSec incident is not evidence about this August event.
The public record does not identify the vendor, the nature or duration of the unusual activity, an initial access vector, affected servers, accessed data, malware, persistence, exfiltration, ransom demand, threat actor, final restoration time or investigative conclusion.

We reported that LexisNexis disconnected from vendor-managed servers after detecting unusual activity, taking Nexis Diligence, Nexis Metabase API and Nexis Newsdesk offline. The company engaged a cybersecurity forensic firm and began rebuilding the services, while the nature of the activity, possible data access, ransomware involvement and attribution remained unresolved.
BleepingComputer reported that LexisNexis took Nexis Diligence, Nexis Metabase API and Nexis Newsdesk offline after unusual activity was detected on vendor-managed servers. Todd Larsen said Nexis Metabase API was unrelated to Metabase Cloud and its recently reported vulnerability; the report did not establish data access, exfiltration, an initial-access method or a threat actor.
The Register reported that Diligence returned during the Aug. 8-9 weekend while its full content catalog was still being restored. Newsdesk and the Metabase API were expected to return progressively Aug. 10, subject to testing. LexisNexis said the event was unrelated to Metabase Cloud and the recently disclosed Metabase vulnerability.
LexisNexis said it identified unusual activity on servers hosted and managed by a third-party vendor. It disconnected from those systems, taking Diligence, Metabase API and Newsdesk offline, engaged a cybersecurity forensic firm and began rebuilding the applications in a new environment before restoration.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
Signed-in members can report an error, update, or missing source.