LexisNexis has taken several services offline after detecting suspicious activity on servers managed by a third-party vendor.
The affected products are Nexis Diligence, Nexis Metabase API and Nexis Newsdesk. The company disconnected from the vendor’s systems to contain the issue.
LexisNexis is now investigating with help from a cybersecurity forensic firm. It plans to rebuild the affected systems in a new environment.
Services taken offline after vendor alert
The company said it detected unusual activity earlier this week. The affected servers were hosted and managed by an unnamed external vendor.
LexisNexis chose to disconnect from those systems immediately. The decision aimed to protect customers and contain the incident.
Todd Larsen, president of LexisNexis’ global Nexis Solutions division, confirmed the service shutdown. He said the investigation and remediation work remain ongoing.
The company has not disclosed the nature of the suspicious activity. It has also not said whether data was accessed or stolen.
Several Nexis products affected
Nexis Diligence is a due diligence and risk research platform. Compliance teams use it to review companies, people and potential risks.
Nexis Metabase API provides news and media data feeds. Businesses can integrate those feeds into internal tools and services.
Nexis Newsdesk supports media monitoring and analytics. Communications, public relations and marketing teams commonly use the platform.
The outage may affect customers that depend on these services for research, monitoring or data integrations. LexisNexis did not provide a restoration timeline.
No link to Metabase Cloud attacks
The shutdown followed recent data-theft attacks against Metabase Cloud. Those attacks used a critical zero-day SQL injection vulnerability.
However, LexisNexis said its Nexis Metabase API product is unrelated to Metabase Cloud. The company also said Nexis Solutions is not a Metabase Cloud customer.
As a result, LexisNexis does not connect the current incident to the reported Metabase Cloud vulnerability.
LexisNexis faced earlier security incidents
This is not the first recent cybersecurity incident involving LexisNexis.
In May 2025, the company disclosed a breach affecting 364,000 people. Attackers gained access to private GitHub repositories and stole personal data.
In March, the threat actor FulcrumSec targeted LexisNexis through the React2Shell flaw. The attackers accessed a limited number of servers in the company’s AWS environment.
LexisNexis said those systems mostly contained legacy data. The company later confirmed that attackers had stolen and leaked private files.
The current incident remains under investigation. Customers should monitor official LexisNexis updates for details about service availability and possible data exposure.


0 responses to “LexisNexis Shuts Down Services After Suspicious Server Activity”