LexisNexis Legal & Professional
Disclosed Mar 3, 20266 months agoUnverified
LexisNexis confirms breach via React2Shell flaw as FulcrumSec leaks files
LexisNexis Legal & Professional confirmed attackers exploited an unpatched React frontend flaw and accessed customer and business data, including about 21,000 customer accounts and roughly 400,000 cloud user profiles, mostly legacy data. FulcrumSec leaked files; no SSNs or financial data were involved.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 3, 2026 |
| Discovered | Feb 24, 2026 |
| Attack | Hacking |
| Data exposed | Names, Emails, IP addresses, Passwords, Messages, API keys |
| Sector | Data brokers · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| LexisNexis confirms data breach as hackers leak stolen filesbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Mar 3 |
Other breaches at LexisNexis Legal & Professional
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Identity thieves used stolen passwords to pull data on 316,000 people from AccurintMar 10, 200521 years agoCredential stuffing | Mar 10, 200521 years ago | Credential stuffing | Data brokers | Settled | 316K |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.