LexisNexis pulls three services offline after suspicious server activity
Data firm takes Diligence, Metabase API, and Newsdesk offline following detection of unusual activity on third-party hosted servers.
Conversation activity · last 37 hours peak 2/hr
Summary, timeline and people extracted by Claude from 6 items across 4 sources · 6h ago. Quotes are verbatim.
LexisNexis took three major services offline last week after detecting unusual activity on servers managed by a third-party vendor, citing the need to protect customer data and system integrity. The company began restoring Diligence over the weekend and expected to bring Newsdesk and Metabase API back online progressively, while working with a cybersecurity forensic firm on the investigation. The outage is unrelated to a separate critical SQL injection vulnerability in Metabase disclosed on August 6.
- LexisNexis took three major data services offline—Diligence, Metabase API, and Newsdesk—after detecting unusual activity on third-party hosted servers, beginning restoration within days.
- The company is working with a cybersecurity forensic firm on the investigation but has not disclosed the nature of the suspicious activity or whether customer data was compromised.
- Affected customers are demanding compensation, with one indicating potential millions in losses given their reliance on the services for client delivery.
- The outage is unrelated to a separate critical SQL injection vulnerability in Metabase disclosed August 6, which has already led to confirmed breaches at other companies.
How it unfolded
-
Customer update indicated Newsdesk and Metabase API expected to come back online progressively during the day, subject to successful testing.
-
Reaction Customer compensation demands
Affected customers stated they would seek compensation from LexisNexis for service disruption, with one source indicating potential millions in damages.
“Businesses like mine pay tens of thousands of pounds a year for these services, and rely on them to serve their own clients. We will be going after them for compensation, and I expect this will end up costing them millions and millions.”
Unnamed affected customer · Hacker News ↗ -
LexisNexis confirmed the outage was not connected to the critical SQL injection vulnerability disclosed by Metabase on August 6, and that Nexis Solutions is not a Metabase Cloud customer.
-
Report Diligence service restored
According to customer update, Diligence returned over the weekend, though LexisNexis was still restoring its full content catalog.
-
LexisNexis identified unusual activity on servers hosted and managed by a third-party vendor and began investigation.
-
LexisNexis took Diligence, Metabase API, and Newsdesk services offline to contain the issue and protect customer data.
“While this decision resulted in those applications going offline, it was the right step to take to ensure the integrity of our own environment and protect our customers and data while our investigation continues.”
Todd Larsen, president of Nexis Solutions · Hacker News ↗ -
Metabase disclosed a critical SQL injection flaw (CVSS 10.0) that has already been linked to at least one breach, including at laptop maker Framework.
What people are saying verbatim
“While this decision resulted in those applications going offline, it was the right step to take to ensure the integrity of our own environment and protect our customers and data while our investigation continues.”
Todd Larsen, President of Nexis Solutions · The Register ↗ · Aug 9
“Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation.”
Todd Larsen, President of Nexis Solutions · The Register ↗ · Aug 9
“Businesses like mine pay tens of thousands of pounds a year for these services, and rely on them to serve their own clients. We will be going after them for compensation, and I expect this will end up costing them millions and millions.”
Unnamed affected customer, LexisNexis customer · The Register ↗ · Aug 9
“Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability.”
LexisNexis, Official statement · The Register ↗ · Aug 9
“Last week, we identified unusual activity on servers that are hosted and managed by a third-party vendor.”
LexisNexis, Official statement · The Register ↗ · Aug 9
Voices from the web unedited
-
LexisNexis pulls data services offline after unusual activity on a third-party vendor’s servers LexisNexis has taken three Nexis products, Diligence, Metabase API, and Newsdesk, offline after detecting unusual activity on a third-party vendor's servers.... https:// itnerd.blog/2026/08/11/lexisne…
-
LexisNexis Shuts Down Services After Suspicious Activitiy On Servers https:// packetstorm.news/news/view/427 07 # news