LexisNexis confirms data breach as hackers leak stolen files
ID: 49ac40e3-4384-5251-9bcf-c4e3d5664b1d
STIX ID: report--49ac40e3-4384-5251-9bcf-c4e3d5664b1d
Feed Name: Bleeping Computer
### Executive summary LexisNexis confirmed an intrusion by the threat actor FulcrumSec who exploited an unpatched React frontend (React2Shell) to gain access to AWS infrastructure and exfiltrate ~2.04 GB of legacy data including Redshift tables, plaintext AWS Secrets Manager secrets, 3.9M database records, ~21k customer accounts, ~400k user profiles and government-affiliated email addresses; the company states the breach is contained and most data is deprecated and does not include SSNs or financial information.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
