LexisNexis confirms data breach as hackers leak stolen files
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述。好的,我得先仔细阅读这篇文章,理解主要信息。 文章讲的是LexisNexis Legal & Professional公司遭受了黑客攻击。黑客通过一个未修补的React应用漏洞进入了他们的AWS服务器,泄露了2GB的数据。这些数据包括客户姓名、用户ID、联系方式等,但不涉及敏感的个人信息或财务信息。公司已经通知执法部门,并聘请了外部专家来协助调查和应对措施。 用户的需求很明确,就是要一个简洁的总结。我需要抓住关键点:黑客入侵、数据泄露、受影响的信息类型、公司的应对措施。同时要注意字数限制在100字以内。 接下来,我要把这些信息浓缩成一句话或几句话,确保涵盖所有重要细节,同时语言简洁明了。比如提到黑客利用React漏洞进入AWS服务器,泄露的数据类型,以及公司采取的措施。 可能还需要检查是否有遗漏的重要信息,比如是否有政府雇员的信息被泄露?文章中提到FulcrumSec声称窃取了超过100个.gov邮箱用户的信息,包括政府员工、法官等。这个点是否需要包含在内?不过考虑到字数限制,可能只能点到为止。 最后,整合这些信息,形成一个流畅的总结句子。 </think> 美国数据分析公司LexisNexis Legal & Professional确认黑客入侵其服务器并访问部分客户和业务信息。威胁行为者FulcrumSec泄露了2GB文件,并声称通过未修补的React应用漏洞进入该公司AWS基础设施。泄露数据主要为旧的非关键信息,未包含敏感个人或财务数据。公司已通知执法部门并聘请外部专家协助调查。 2026-3-3 15:45:15 Author: www.bleepingcomputer.com(查看原文) 阅读量:15 收藏

LexisNexis confirms data breach as hackers leak stolen files

American data analytics company LexisNexis Legal & Professional has confirmed to BleepingComputer that hackers breached its servers and accessed some customer and business information.

The company's data breach confirmation comes as a threat actor named FulcrumSec leaked 2GB of files on various underground forums and sites.

LexisNexis L&P is a global provider of legal, regulatory, and business information, research tools, and analytics used by lawyers, corporations, governments, and academic institutions in more than 150 countries worldwide.

Cloud breach via unpatched React app

The threat actor says that on February 24 they gained access to the company's AWS infrastructure by exploiting the React2Shell vulnerability in an unpatched React frontend app.

LexisNexis L&P admitted that hackers breached its network, noting that the stolen information was old and consisted mostly of non-critical details.

“Our investigation has confirmed that an unauthorized party accessed a limited number of servers,” the company told BleepingComputer.

“These servers contained mostly legacy, deprecated data from prior to 2020, including information such as customer names, user IDs, business contact information, products used, customer surveys with respondent IP addresses, and support tickets,” a spokesperson said.

“The impacted information did not contain Social Security numbers, driver’s license numbers, or any other sensitive personally identifiable information; credit card, bank accounts, or any other financial information; active passwords; or customer search queries, customer client or matter information, or customer contracts.”

Based on its investigation, LexisNexis believes that the intrusion has been contained and found no evidence that products or services were impacted by the intrusion.

In a public post detailing the hack, FulcrumSec claims that they stole information related to more than 100 users with .gov email addresses, which included U.S. government employees, federal judges and law clerks, U.S. Department of Justice attorneys, and U.S. SEC staff.

The threat actor detailed the intrusion, saying that they "exfiltrated 2.04 GB of structured data from LexisNexis AWS infrastructure" via a vulnerable React container with access to:

  • 536 Redshift tables
  • 430+ VPC database tables
  • 53 AWS Secrets Manager secrets in plaintext
  • 3.9M database records
  • 21,042 customer accounts
  • 5,582 attorney survey respondents
  • 45 employee password hashes
  • Complete VPC infrastructure mapping

FulcrumSec said that they also had access to around 400,000 cloud user profiles that included real names, emails, phone numbers, and job functions. According to the hackers, 118 users had .gov addresses belonging to U.S. government employees, federal judges and law clerks, U.S. Department of Justice attorneys, and U.S. SEC staff.

FulcrumSec's post for LexisNexis data leak
FulcrumSec's post for LexisNexis data leak
Source: BleepingComputer

FulcrumSec said that they contacted LexisNexis, but the company "decided not to work with us on this." They also criticized the company’s security practices that permitted a single ECS task role "read access to every secret in the account, including the production Redshift master credential."

LexisNexis has notified law enforcement and contracted an external cybersecurity expert to assist with the investigation and implementation of containment measures.

The company has taken responsibility for the breach and informed current and previous customers of the intrusion.

Last year, the company disclosed another breach after hackers compromised a corporate account and accessed sensitive information belonging to 364,000 customers.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/
如有侵权请联系:admin#unsafe.sh