LexisNexis Confirms Data Breach After Hackers Leak Stolen Files Online

Related

South Korea Fines Coupang $400M Over Data Breach Affecting Millions

What happened South Korea fined online retail giant Coupang more...

ServiceNow Discloses Security Incident Exposing Customer Data

What happened ServiceNow disclosed a security incident after attackers exploited...

Lansing Community College Data Breach Impacts 174,000 People

What happened Lansing Community College is notifying more than 174,000...

SoFi Confirms Third-Party Data Breach at Hong Kong Subsidiary

What happened SoFi Hong Kong confirmed a data breach after...

Meta AI Support Data Breach Affects Over 20,000 Instagram Accounts

What happened Meta revealed that more than 20,000 Instagram users...

Share

What happened

LexisNexis Legal & Professional confirmed that hackers breached its servers and accessed some customer and business information after a threat actor named FulcrumSec leaked approximately 2 GB of stolen files on underground forums and file-sharing sites. The leaked dataset reportedly contains internal documents, configuration files, and information linked to company systems and customers. LexisNexis stated it is investigating the incident and assessing the scope of the exposure while working to determine what data was accessed and whether customers were impacted. 

Who is affected

Customers and organizations using services provided by LexisNexis Legal & Professional may be affected, as the breach involved company systems containing customer and internal business information. 

Why CISOs should care

The breach highlights risks to organizations that rely on large data analytics and legal information platforms, where compromise of vendor systems can expose sensitive internal or customer-related data. 

3 practical actions

  1. Review vendor exposure risks. Assess potential impact if LexisNexis services or data are integrated into internal systems. 
  2. Monitor for leaked internal documents. Track underground forums and leak sites for data associated with the breach. 
  3. Evaluate third-party data security practices. Review controls governing access to external data platforms used by the organization. 
IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.