LexisNexis Shuts Down Key Services Following Suspicious Vendor Activity
Global data analytics giant **LexisNexis** has temporarily taken its **Diligence**, **Metabase API**, and **Newsdesk** services offline. This decisive action follows the discovery of unusual activity on servers managed by an unnamed third-party vendor, prompting an immediate investigation and system rebuild.
Global data analytics company **LexisNexis** has proactively disconnected several critical services after detecting suspicious activity on servers hosted and managed by a third-party vendor. The affected platforms β **Nexis Diligence**, **Nexis Metabase API**, and **Nexis Newsdesk** β are now offline as the company works to investigate and remediate the issue.

### Immediate Disconnection for Security
In a notification to customers, **LexisNexis** stated, "Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor. To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems."
The company is currently working with a cybersecurity forensic firm to investigate the incident thoroughly. Their strategy includes rebuilding affected systems in a new, secure environment before bringing the services back online.

### Critical Services Affected
**LexisNexis** provides essential legal, business, regulatory, and risk information services to a broad client base, including corporations, law firms, financial institutions, and government agencies.
* **Nexis Diligence** is a vital platform for compliance professionals conducting due diligence and risk research.
* **Nexis Metabase API** supplies news and media data feeds for integration into enterprise systems.
* **Nexis Newsdesk** is a media monitoring and analytics service primarily used by communications and marketing teams.
**Todd Larsen**, president of the global **Nexis Solutions** division of **LexisNexis**, confirmed the service shutdown was a direct response to the suspicious activity on vendor servers. He stated, βOur investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation.β
### Clarification on Metabase Cloud Vulnerability
This incident follows recent news of a critical zero-day SQL injection vulnerability impacting **Metabase Cloud** hosting services, which led to data-theft attacks. However, **Larsen** clarified that **Nexis Solutions** is not a **Metabase Cloud** customer, and their **Nexis Metabase API** product is entirely unrelated to **Metabase Cloud** or the reported vulnerability.
### A History of Incidents
This is not the first time **LexisNexis** has faced cybersecurity challenges. In May 2025, the company disclosed a data breach affecting 364,000 individuals after unauthorized access to its private **GitHub** repositories. Earlier this year, in March, a threat actor named '**FulcrumSec**' exploited a '**React2Shell**' flaw in the company's **AWS** infrastructure, leading to the theft and subsequent leak of private files. At that time, **LexisNexis** confirmed unauthorized access to a limited number of servers, primarily containing legacy data.