LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen
On March 3, 2026, an individual using the alias FulcrumSec claimed responsibility for a security breach impacting LexisNexis Legal & Professional, a division of RELX Group. The breach allegedly resulted in the unauthorized extraction of 2.04 GB of…
On March 3, 2026, an individual using the alias FulcrumSec claimed responsibility for a security breach impacting LexisNexis Legal & Professional, a division of RELX Group. The breach allegedly resulted in the unauthorized extraction of 2.04 GB of structured data from the company's AWS cloud infrastructure.
Initial access was reportedly obtained on February 24, 2026, by exploiting the React2Shell vulnerability in an unpatched React frontend application. The threat actor utilized a compromised ECS task container, known as LawfirmsStoreECSTaskRole , which had read access to several critical resources including:
Production Redshift data warehouse 17 VPC databases AWS Secrets Manager Qualtrics survey platform
The security posture of the company was criticized by the actor, noting that the RDS master password was set to a weak default and that a single task role had extensive access to AWS account secrets, including production database credentials.
Data Asset Alleged Volume
Redshift Tables 536
VPC Database Tables 430+
The breach allegedly resulted in the unauthorized extraction of 2.04 GB of structured data from the company's AWS cloud infrastructure.
AWS Secrets Manager Secrets (Plaintext) 53
Total Database Records 3.9 Million
Cloud User Profiles ~400,000
Enterprise Customer Accounts 21,042
Employee Password Hashes 45
.gov Email Users Exposed 118
The breach reportedly exposed approximately 400,000 cloud user profiles containing personal information. Among these, 118 profiles were linked to .gov email addresses associated with federal officials.
Additionally, the actor claims to have acquired a complete VPC infrastructure map and a full AWS Secrets Manager dump containing 53 plaintext secrets.
FulcrumSec clarified that this incident is distinct from the December 2024 GitHub breach, which involved a different data compromise related to a third-party software development platform.
This incident highlights significant potential security vulnerabilities within a major legal data repository.
Based on reporting by Cyber Security News.
