New York-based LexisNexis disconnected from vendor-managed servers after detecting unusual activity, taking three customer-facing research and data products offline while forensic specialists investigate.
The affected products are Nexis Diligence, which supports due diligence and risk research; Nexis Metabase API, which delivers news data to other systems; and Nexis Newsdesk, a media-monitoring service.
A customer update obtained by BleepingComputer said LexisNexis disconnected from the vendor’s systems, hired a cybersecurity forensic firm and began rebuilding the applications in a new environment.

LexisNexis said it kept the products offline to protect customers and its own systems during the investigation.
Beyond describing the server activity as unusual, LexisNexis has not explained its nature or scope or said whether anyone accessed or removed information. The company also has not disclosed an initial access method, malware, a ransom demand or a threat actor.
Metabase, a separate analytics software company, recently said attackers exploited a previously unknown flaw in its hosted Metabase Cloud service. Because one affected LexisNexis product has a similar name, Todd Larsen, president of the company’s global Nexis Solutions division, told BleepingComputer that Nexis Solutions does not use Metabase Cloud and that the disruption is unrelated to the vulnerability.
New York-headquartered LexisNexis provides legal, regulatory, news and business information to customers in almost 150 countries and territories.
LexisNexis’ precautionary shutdown echoes a July response by Massachusetts-based Progress Software, which restored ShareFile cloud access while keeping customer-managed storage servers offline during a security investigation.
No public update reviewed Tuesday confirmed that all three LexisNexis applications had returned to service as the company continued rebuilding them.