US data analytics firm LexisNexis Legal & Professional has confirmed it has suffered a security breachafter a 2GB file leak by a hacking group called FulcrumSec. The incident has once again highlighted the dangers of cloud infrastructure, even for organizations with a global footprint.

LexisNexis L&P is one of the largest providers of legal, regulatory and business information globally, serving law firms, governments, corporations and universities in more than 150 countries. Its tools and databases are used daily for legal research, due diligence and regulatory compliance, making any security incident particularly sensitive.
See also: Cloudflare: Ready to face any cyber threat from Iran
LexisNexis: The attack via AWS and the React2Shell vulnerability
According to FulcrumSec, the access was gained on February 24th through the exploitation of the React2Shell in an unpatched React. The vulnerability allegedly opened the way to the infrastructure AWS company's, allowing lateral movement within the cloud environment.
LexisNexis itself admitted that an unauthorized third party gained access to a limited number of servers. As it clarified, the data exposed was mostly old and related to periods before 2020. This included customer names, user IDs, company contact information, information about products used, support requests and research data with IP addresses.
The company said no social security numbers, IDs, financial information, active passwords , or customer and case search data. It also said there was no indication of product or service disruption and that the breach has been contained.

The claims of FulcrumSec for extensive access
FulcrumSec, however, presents a more extensive picture of the breach. In a public post, it claims to have gained access to 536 Redshift tables, more than 430 VPC database tables , and 53 AWS Secrets Manager secrets in plain text. It also mentions 3.9 million database records, 21,042 customer accounts , and a complete mapping of the VPC infrastructure.
See also: Cloud Imperium Games: Data breach affects gamers
The data is particularly sensational, claiming that it included information for more than 100 users with email addresses .gov, including US government employees, federal judges, Justice Department officials and Securities and Exchange Commission staff. The group also says it gained access to about 400,000 cloud user profiles with real names, emails and phone numbers.
The hackers also claim that an ECS task role had overly broad privileges, allowing read access to all account secrets, including the production Redshift master credential. If confirmed, this finding raises serious questions about privilege management practices and the least privilege model.
Response, investigation and previous incident
LexisNexis announced that it informed law enforcement authorities and hired an external cyber security specialist to investigate and implement mitigation measures. At the same time, it informed current and former customers, taking responsibility for the incident.
See also: SloppyLemming targets critical infrastructure in Pakistan and Bangladesh

The incident comes just a year after another breach, in which data from approximately 364,000 customers was affected through a compromised corporate account. The recurrence of incidents within a short period of time highlights the ongoing pressure on large data providers and the importance of continuously upgrading defense mechanisms.
The broader message for security in the cloud
The case highlights a critical issue for the industry: even mature cloud infrastructures can become vulnerable when applications are not updated in a timely manner or when access rights are not strictly restricted. In an environment where legal and regulatory information is a strategic asset, security is not just a technical issue, but a pillar of trust and reputation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
