2026 LexisNexis Legal & Professional — 3.9M records (FulcrumSec, React2Shell / Reach2Shell)
Data compromised
Names, business contact info, user IDs, support/ticket context, IP-related data; no highly sensitive PII confirmed in LexisNexis public statements
Technical writeup
LexisNexis Legal & Professional (separate from LexisNexis Risk Solutions) confirmed a data breach in early March 2026. Some headlines conflate this with the Risk Solutions cloud incident (~364K profiles in public filings); the ~3.9M figure applies here (Legal & Professional), not Risk. Threat actor FulcrumSec exploited an unpatched React2Shell-class vulnerability (also referred to as Reach2Shell in some analyses) in a React frontend application. Attackers accessed an AWS-hosted environment with broad read permissions, including Redshift data warehouses—about 3.9M database records touched in public estimates. Compromised data included cloud user profiles with names, emails, and phones; customer account metadata; support-ticket context; and IP-related telemetry in some summaries. LexisNexis stated much of the content was legacy, pre-2020 data; no SSNs, payment cards, or active passwords in the impacted set per company statements.
Root cause
Unpatched React2Shell / Reach2Shell-class flaw; AWS misconfiguration enabling broad reads