Hand on keyboard showing cyber attack on data services

LexisNexis Shuts Down Data Services Following Third-Party Cyber Attack

Legal AI solutions company LexisNexis was forced to pull its data services offline after detecting suspicious activity on its managed third-party vendor’s environment, disrupting access to critical investigative tools.

“Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” the company stated.

LexisNexis is working to restore the impacted systems and has hired an external cybersecurity forensics firm to respond to the incident.

Cyber attack shuts down LexisNexis data services

The disruption affected LexisNexis Diligence, a background and compliance checks platform, Newsdesk, a public-facing news monitoring platform, and Metabase API, a developer-centric news aggregation system that helps customers monitor and ingest news, social media content, and historical printed content into their products.

However, the company clarified that its Metabase platform was unrelated to the Metabase Cloud platform that was recently affected by a critical SQL injection vulnerability (CVSS 10.0).

Meanwhile, LexisNexis says it was working to restore the impacted data services progressively to ensure the security of customer information. However, LexisNexis restored Diligence shortly after, while other data services remained inaccessible.

“An outage like this doesn’t announce itself as a security story. It shows up as teams that suddenly can’t see what they could see yesterday, even though nothing in their own environment changed,” said Amit Shuster, VP Product & Engineering, Vetric.

At the moment, LexisNexis has hired external cybersecurity experts to respond and investigate the incident to determine its scope. Companies typically take days, weeks or even months to determine the full scope of the breach.

“Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation,” LexisNexis said.

The legal solutions company also justified its decision to disconnect the data services to protect customer data from unauthorized access.

The company will also seek compensation from the third-party vendor to offset losses stemming from the disruption of its data services. Nevertheless, the company has not disclosed whether it had cybersecurity insurance, which could also offset some of the losses.

“For investigators and trust and safety teams working time-sensitive cases, lost visibility means a stalled case, and threats don’t pause while service is restored,” added Shuster. “That’s why the organizations on the front lines are getting deliberate about resilience, working with partners alongside their existing sources, so one provider’s bad week never becomes their blind spot.”

So far, LexisNexis has not attributed the data services hack to any cyber extortion gang, and no group has taken responsibility. The identity of the affected third-party vendor also remains undisclosed. Similarly, the legal solutions provider has not confirmed whether the threat actors exfiltrated customer data from the third-party-managed system.

Legal technology companies and law firms targeted by cybercriminals

Legal services companies and law firms are frequently targeted because of the sensitive information they collect from their customers, especially enterprise clients.

LexisNexis has experienced a cyber attack in the past. In February 2026, cybercrime gang FulcrumSec breached the company’s AWS infrastructure after exploiting critical vulnerability (CVSS 10.0) CVE-2025-55182 in the React frontend app codenamed React2Shell and leaked 2 GB of stolen data. In May 2025, hackers also breached the company’s private GitHub repositories and compromised the personal data of 364,000 customers.

In 2026, Goodwin Procter experienced a data breach affecting a limited number of clients after an employee fell victim to a phishing attack. In July 2026, Pillsbury Winthrop Shaw Pittman LLP also disclosed a cyber incident stemming from a social engineering attack.

Legal services platforms and technology companies, the Legal Aid Agency (U.K.), LegalWise South Africa, the U.K.’s Police National Legal Database (PNLD), and Docketwise also experienced data breaches that could have resulted in unauthorized access to customer data.