logo

LexisNexis confirms data breach as hackers leak stolen files

ID: 49ac40e3-4384-5251-9bcf-c4e3d5664b1d

STIX ID: report--49ac40e3-4384-5251-9bcf-c4e3d5664b1d

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

### Executive summary LexisNexis confirmed an intrusion by the threat actor FulcrumSec who exploited an unpatched React frontend (React2Shell) to gain access to AWS infrastructure and exfiltrate ~2.04 GB of legacy data including Redshift tables, plaintext AWS Secrets Manager secrets, 3.9M database records, ~21k customer accounts, ~400k user profiles and government-affiliated email addresses; the company states the breach is contained and most data is deprecated and does not include SSNs or financial information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.