LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen
ID: 0e880584-96f6-50f2-af6f-114bd8a413ca
STIX ID: report--0e880584-96f6-50f2-af6f-114bd8a413ca
Feed Name: cybersecurityNews.com
FulcrumSec claims to have breached LexisNexis Legal & Professional by exploiting the React2Shell vulnerability in an unpatched React frontend and abusing an ECS task role to read production Redshift, multiple VPC databases, AWS Secrets Manager, and other assets; the actor alleges exfiltration of 2.04 GB of structured data including 3.9M records, ~400,000 cloud user profiles (118 .gov addresses), 53 plaintext secrets, and enterprise/employee data, and highlights weak credentials and misconfigurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
