2026 LexisNexis Risk Solutions — FulcrumSec AWS breach (~364K profiles; React2Shell / Reach2Shell)
Data compromised
Names, business contact info, user IDs, support tickets, IP-related data; highly sensitive PII not confirmed in firm statements
Technical writeup
LexisNexis Risk Solutions confirmed a cloud data breach disclosed in March 2026 (distinct from the LexisNexis Legal & Professional ~3.9M-record incident in the same timeframe—some media incorrectly attributes ~3.9M records to Risk; that figure aligns with Legal & Professional, breach id lexisnexis-legal2026). Threat actor FulcrumSec exploited an unpatched React2Shell-class issue (Reach2Shell naming in some reports) in AWS-facing infrastructure. Press and vendor summaries cited roughly 364,000 impacted profiles, with ~2 GB exfiltrated across large numbers of Redshift/VPC tables and exposure of Secrets Manager material in some analyses. Data included names, business contact fields, user identifiers, support-ticket content, and IP-related metadata; LexisNexis stated SSNs and payment card data were not in the accessed datasets.
Root cause
Exploitation of unpatched React2Shell / Reach2Shell-class vulnerability; AWS over-broad permissions