Skip to content

Three LexisNexis services remain offline during vendor-server probe

The company is rebuilding Diligence, Metabase API and Newsdesk in a new environment after isolating the affected systems.

Three LexisNexis services remain offline during vendor-server probe
A LexisNexis sign is displayed on an office building. The company took three Nexis services offline while investigating unusual activity on vendor-managed servers.

New York-based LexisNexis disconnected from vendor-managed servers after detecting unusual activity, taking three customer-facing research and data products offline while forensic specialists investigate.

The affected products are Nexis Diligence, which supports due diligence and risk research; Nexis Metabase API, which delivers news data to other systems; and Nexis Newsdesk, a media-monitoring service.

A customer update obtained by BleepingComputer said LexisNexis disconnected from the vendor’s systems, hired a cybersecurity forensic firm and began rebuilding the applications in a new environment.

Screenshot of a LexisNexis customer notice describing the shutdown of Diligence, Metabase API and Newsdesk after unusual activity on third-party-managed servers.
A LexisNexis customer notice obtained by BleepingComputer says the company took Diligence, Metabase API and Newsdesk offline after detecting unusual activity on third-party-managed servers. (Screenshot via BleepingComputer)

LexisNexis said it kept the products offline to protect customers and its own systems during the investigation.

Beyond describing the server activity as unusual, LexisNexis has not explained its nature or scope or said whether anyone accessed or removed information. The company also has not disclosed an initial access method, malware, a ransom demand or a threat actor.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

Metabase, a separate analytics software company, recently said attackers exploited a previously unknown flaw in its hosted Metabase Cloud service. Because one affected LexisNexis product has a similar name, Todd Larsen, president of the company’s global Nexis Solutions division, told BleepingComputer that Nexis Solutions does not use Metabase Cloud and that the disruption is unrelated to the vulnerability.

New York-headquartered LexisNexis provides legal, regulatory, news and business information to customers in almost 150 countries and territories.

LexisNexis’ precautionary shutdown echoes a July response by Massachusetts-based Progress Software, which restored ShareFile cloud access while keeping customer-managed storage servers offline during a security investigation.

No public update reviewed Tuesday confirmed that all three LexisNexis applications had returned to service as the company continued rebuilding them.

DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Private Sector

See all

More from DysruptionHub Staff

See all