logo

LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen

ID: 0e880584-96f6-50f2-af6f-114bd8a413ca

STIX ID: report--0e880584-96f6-50f2-af6f-114bd8a413ca

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Guru Baran

...
...

FulcrumSec claims to have breached LexisNexis Legal & Professional by exploiting the React2Shell vulnerability in an unpatched React frontend and abusing an ECS task role to read production Redshift, multiple VPC databases, AWS Secrets Manager, and other assets; the actor alleges exfiltration of 2.04 GB of structured data including 3.9M records, ~400,000 cloud user profiles (118 .gov addresses), 53 plaintext secrets, and enterprise/employee data, and highlights weak credentials and misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.