LexisNexis Confirms Data Breach After Hackers Leak Stolen Files Online

Related

KDDI Confirms Zero-Day Exploit Behind Breach Affecting 12 Million People

What happened KDDI has updated its earlier breach disclosure, confirming...

Aflac Japan Data Breach Impacts 4.38 Million Customers and Agents

What happened Aflac Life Insurance Japan disclosed a data breach...

Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day Attacks

What happened Nissan disclosed a data breach affecting current and...

KDDI Breach Exposes Up to 14.2 Million Email Logins at Six ISPs

What happened Japanese telecommunications operator KDDI disclosed a data breach...

Xsolis Data Breach Affects 1.4 Million Individuals

What happened Healthcare technology company Xsolis disclosed a data breach...

Share

What happened

LexisNexis Legal & Professional confirmed that hackers breached its servers and accessed some customer and business information after a threat actor named FulcrumSec leaked approximately 2 GB of stolen files on underground forums and file-sharing sites. The leaked dataset reportedly contains internal documents, configuration files, and information linked to company systems and customers. LexisNexis stated it is investigating the incident and assessing the scope of the exposure while working to determine what data was accessed and whether customers were impacted. 

Who is affected

Customers and organizations using services provided by LexisNexis Legal & Professional may be affected, as the breach involved company systems containing customer and internal business information. 

Why CISOs should care

The breach highlights risks to organizations that rely on large data analytics and legal information platforms, where compromise of vendor systems can expose sensitive internal or customer-related data. 

3 practical actions

  1. Review vendor exposure risks. Assess potential impact if LexisNexis services or data are integrated into internal systems. 
  2. Monitor for leaked internal documents. Track underground forums and leak sites for data associated with the breach. 
  3. Evaluate third-party data security practices. Review controls governing access to external data platforms used by the organization. 
IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.