← LexisNexis

2026 LexisNexis — third-party vendor incident hits Diligence / Metabase API / Newsdesk (Aug)

2026 Unknown records affected Share on X

Data compromised

Unclear at indexing — LexisNexis said forensic investigation was underway and did not confirm customer-data exposure. Service disruption to Diligence, Metabase API and Newsdesk confirmed.

Technical writeup

Company-confirmed third-party disruption — In the same reporting wave as Metabase’s zero-day disclosure, LexisNexis emailed customers that unusual activity on third-party-hosted servers led it to disconnect Diligence, Metabase API and Newsdesk to contain the issue. Availability was impacted; whether customer data was copied was not confirmed at indexing time, so recordsAffected is 0. Distinct from LexisNexis Risk Solutions and Legal & Professional FulcrumSec/React2Shell incidents earlier in 2026 (lexisnexis2026 / lexisnexis-legal2026). Update if LexisNexis publishes a data-exposure notice.

Root cause

Unusual activity on servers hosted/managed by a third-party vendor; LexisNexis disconnected from those systems. Covered alongside Metabase zero-day victim disclosures; company email referenced Metabase API among affected services.

References