Cyber Security News

LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen

A threat actor operating under the alias FulcrumSec has publicly claimed responsibility for a fresh breach of LexisNexis Legal & Professional, the legal information division of RELX Group, alleging the exfiltration of 2.04 GB of structured data from the company’s AWS cloud infrastructure.

According to FulcrumSec’s post published on March 3, 2026, initial access was gained on February 24 by exploiting the React2Shell vulnerability in an unpatched React frontend application, a flaw the company had reportedly left unaddressed for months.

The threat actor leveraged the compromised LawfirmsStoreECSTaskRole ECS task container, which had been granted read access to the production Redshift data warehouse, 17 VPC databases, AWS Secrets Manager, and the Qualtrics survey platform.

Alleged Leak Claim

Notably, the actor criticized the company’s security posture, pointing out that the RDS master password was set to “Lexis1234”, and that a single task role held read access to every secret in the AWS account, including production database master credentials.

Data AssetAlleged Volume
Redshift Tables536
VPC Database Tables430+
AWS Secrets Manager Secrets (Plaintext)53
Total Database Records3.9 Million
Cloud User Profiles~400,000
Enterprise Customer Accounts21,042
Employee Password Hashes45
.gov Email Users Exposed118

FulcrumSec alleges that among the 400,000 cloud user profiles containing real names, emails, phone numbers, and job functions, 118 accounts held .gov email addresses belonging to federal judges, federal court law clerks, U.S. Department of Justice attorneys, and U.S. SEC staff.

The actor also claims to have obtained a complete VPC infrastructure map and the full AWS Secrets Manager dump with 53 plaintext secrets.

FulcrumSec explicitly noted this is not related to the December 2024 GitHub breach, in which an unauthorized party stole personal data, including Social Security numbers of over 364,000 individuals, via LexisNexis’s third-party software development platform.

The recurrence raises significant concerns about systemic security gaps within one of the world’s most sensitive legal data repositories.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago