“Earlier this week, we identified unusual activity on servers that are hosted and managed by a third‑party vendor,” reads a customer notification from LexisNexis — a terse sentence that set in motion the immediate removal of three widely used services from the company’s public infrastructure.
LexisNexis disconnects Diligence, Metabase API, and Newsdesk
LexisNexis took Nexis Diligence, the Nexis Metabase API, and Nexis Newsdesk offline after spotting the activity. The company said the move was "to protect our customers and contain the issue at its source," according to the notification sent to customers last week.
Those three products serve distinct user groups: Nexis Diligence is a due diligence and risk research platform used by compliance professionals; the Nexis Metabase API provides news and media data feeds for integration into enterprise systems; and Nexis Newsdesk is a media monitoring and analytics service used primarily by communications, public relations, and marketing teams. LexisNexis itself is described in the notice as a global data analytics company providing legal, business, regulatory, and risk information research, public records, and risk management services to corporations, law firms, financial institutions, government agencies, consultants, and researchers.
Investigation with a cybersecurity forensic firm and a system rebuild
Todd Larsen, president of the global Nexis Solutions division at LexisNexis, confirmed to BleepingComputer that the services were taken down because of suspicious activity on vendor servers. "Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation," Larsen said.
LexisNexis said it is rebuilding affected systems in a new environment before restoring service, and that it disconnected from the implicated third‑party systems as an immediate containment step. The company did not name the vendor in its customer notification.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleVendor‑hosted servers and the Metabase Cloud clarification
The disruption came amid public reports that Metabase’s Cloud hosting service had been targeted in data‑theft attacks exploiting a critical zero‑day SQL injection vulnerability. In a clarification to BleepingComputer, Larsen said that Nexis Solutions is not a Metabase Cloud customer and that "the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability."
LexisNexis’s account therefore separates the company’s Metabase API product, which provides news feeds for enterprise integration, from the Metabase Cloud incident reported elsewhere; the decision to take services offline was linked, the company said, to unusual activity observed on servers hosted and managed by an unnamed third‑party vendor.
Earlier breaches in 2025 that shape the backdrop
The company’s current response arrives against a recent string of cybersecurity incidents. In May 2025 LexisNexis disclosed that hackers had stolen personal data for 364,000 individuals after gaining unauthorized access to the company’s private GitHub repositories. Earlier in the same year, in March, the company was targeted by the threat actor "FulcrumSec" after the actor exploited the "React2Shell" flaw in LexisNexis’s AWS infrastructure to steal and later leak private files; at the time LexisNexis confirmed unauthorized access to "a limited number of servers," which it said contained mostly legacy data.
What this means for compliance professionals, communications teams, and security teams
- Compliance professionals who rely on Nexis Diligence for due diligence and risk research will face immediate disruption to those workflows while the platform is offline and being rebuilt.
- Communications, public relations, and marketing teams that use Nexis Newsdesk for media monitoring and analytics should expect gaps in monitoring and data feeds until the service is fully restored from the new environment.
- Security teams and enterprise procurement leaders will watch the investigation and the unnamed third‑party vendor closely; LexisNexis’s decision to work with a forensic firm and to rebuild systems in a new environment signals containment and remediation are the current operational priorities.
LexisNexis has moved quickly to isolate the problem and to frame remediation steps: disconnect from the affected vendor systems, investigate with external forensic support, and rebuild in a new environment before restoring service. The next concrete milestones are straightforward and publicly stated — the forensic review’s findings and the timeline for bringing Nexis Diligence, Nexis Metabase API, and Nexis Newsdesk back online. They will determine how long dependent organizations must operate without those services and how broadly the vendor‑hosted activity extended.




