LexisNexis Faces Data Breach After 2.04 GB of Data Allegedly Stolen
ID: feb7b965-e63c-5508-9cc8-64109757d89a
STIX ID: report--feb7b965-e63c-5508-9cc8-64109757d89a
Feed Name: GBHackers
FulcrumSec claims to have breached LexisNexis Legal & Professional by exploiting an unpatched React2Shell vulnerability to compromise an ECS task role (LawfirmsStoreECSTaskRole) and exfiltrate 2.04 GB of data — allegedly 3.9 million records, 536 Redshift tables, 430+ VPC tables, ~400,000 cloud user profiles (including 118 .gov users), 53 plaintext AWS Secrets, and production database credentials; the report highlights weak credential management (e.g., an RDS master password of "Lexis1234") and overly permissive AWS access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
