LexisNexis pulls three services offline after suspicious server activity
off-prem
Customers say issues began Wednesday and still not resolved
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline last week after detecting "unusual activity on servers that are hosted and managed by a third-party vendor."
Non-public customer communications penned by Todd Larsen, president of Nexis Solutions, and seen by The Register, said the company took the decision to protect customers by "containing the issue at its source" and "disconnecting from those third-party systems."
"While this decision resulted in those applications going offline, it was the right step to take to ensure the integrity of our own environment and protect our customers and data while our investigation continues," said Larsen.
"Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation."
Customers told us the outage began on Wednesday and remained ongoing.
According to a customer update sent on Monday morning, Diligence returned over the weekend, although LexisNexis was still restoring its full content catalog.
Newsdesk and Metabase API were expected "to come back online progressively over the course of the day," the update said.
"This timing is subject to successful testing, and we will keep you informed of any changes."
One source said they would be seeking compensation from LexisNexis owing to the service disruption.
"Businesses like mine pay tens of thousands of pounds a year for these services, and rely on them to serve their own clients," they said. "We will be going after them for compensation, and I expect this will end up costing them millions and millions."
Nexis Diligence is a tool for employers to run background and compliance checks on individuals and entities, while Newsdesk is a news-monitoring service. LexisNexis Metabase API supplies near-real-time news and social media content for ingestion into customers' applications. Despite the name, it is unrelated to the Metabase business intelligence platform.
A LexisNexis spokesperson confirmed that the outage was not connected to the critical SQL injection flaw disclosed by Metabase on August 6. That separate vulnerability, rated CVSS 10.0 but not yet assigned a CVE, has already been linked to at least one confirmed breach at laptop maker Framework.
The company told The Reg: "Last week, we identified unusual activity on servers that are hosted and managed by a third-party vendor. Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation.
It added: "Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability."
LexisNexis did not answer our questions about the nature of the "unusual activity" it reported, nor whether any data was compromised during this time.
The company's Legal & Professional division was targeted by Fulcrumsec earlier this year, leading to a breach of customer records.
The attackers used the React2Shell vulnerability to break in and steal what LexisNexis said was "mostly legacy, deprecated data from prior to 2020."
A year earlier, on April Fool's Day, LexisNexis discovered a breach at its Risk Solutions arm that compromised data belonging to around 360,000 people. ®
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)