Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
underground-data-leakbreach-disclosure-notificationcloud-service-vulnerabilitycloud-misconfiguration

LexisNexis Legal & Professional AWS Breach and FulcrumSec Data Leak

Updated 3mo agoFirst seen Mar 3, 20267 sources

LexisNexis Legal & Professional confirmed that an unauthorized party accessed a limited number of its servers after a threat actor using the alias FulcrumSec leaked roughly 2 GB of allegedly stolen files on underground forums. LexisNexis stated the exposed information was mostly legacy/deprecated data from prior to 2020 (e.g., customer names, user IDs, business contact details, products used, customer survey data including respondent IP addresses, and support tickets) and said it found no evidence of impact to products or services; the company reported the matter to law enforcement and engaged an external forensics firm.

FulcrumSec claimed the intrusion began by exploiting the React2Shell vulnerability in an unpatched React frontend application to gain access to LexisNexis’ AWS environment, and alleged broader access within cloud resources (including an ECS task role and data stores) and the presence of government-related accounts (e.g., .gov email addresses) in the stolen dataset. Public reporting notes a discrepancy between the actor’s claims (e.g., “millions of records,” passwords, and other internal artifacts) and LexisNexis’ characterization of the exposed data as limited and non-sensitive (no SSNs, financial data, active passwords, or customer search queries), but multiple outlets corroborated that the leaked files are tied to a real, now-contained incident affecting LexisNexis’ Legal & Professional division.

Share:
LexisNexis Legal & Professional AWS Breach and FulcrumSec Data Leak
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 3, 20264mo ago

LexisNexis confirms contained breach and notifies customers and law enforcement

LexisNexis Legal & Professional confirmed that attackers accessed a limited number of servers containing mostly legacy or deprecated pre-2020 data and said the incident had been contained with no evidence of impact to products or services. The company said it engaged an external forensics firm, notified law enforcement, and informed affected current and former customers, while stating that highly sensitive data such as Social Security numbers, financial data, and active passwords were not exposed.

FulcrumSec leaks purported LexisNexis data on underground forums

After the intrusion, FulcrumSec publicly posted or advertised roughly 2 GB of purported LexisNexis data on cybercrime forums, claiming the dump contained millions of records, including customer and business information. The leak prompted public scrutiny and media reporting about the scope of the alleged compromise.

Feb 24, 20264mo ago

FulcrumSec allegedly breaches LexisNexis via React2Shell exploit

Multiple reports say the threat actor FulcrumSec claimed initial access to LexisNexis Legal & Professional on February 24, 2026 by exploiting an unpatched React frontend application, leading to access to the company's AWS environment. The actor alleged it could reach Redshift, VPC databases, Secrets Manager, and other cloud assets and exfiltrate about 2.04 GB of data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Threat actors
1 linked
Affected products
2 linked
ReactGithub
Organizations
14 linked
BleepingComputerLexisNexisAutomoxArctic WolfBlackpoint CyberMicrosoft CorporationGitHubSemperis1Ready1Amazon Web ServicesLexisNexis Legal & ProfessionalLexisNexis Risk SolutionsRelxQualtrics
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.