New LexisNexis Data Breach Confirmed After Hackers Leak Files

New LexisNexis Data Breach Confirmed After Hackers Leak Files

LexisNexis confirmed a data breach after hackers leaked data allegedly stolen from its systems, saying the impact is limited and that compromised servers primarily held legacy data from before 2020. The attackers claimed to exploit the React2Shell vulnerability and misconfigured AWS instances to exfiltrate over 2GB of data, allegedly including enterprise records, employee credentials, and personal information for roughly 400,000 people. #LexisNexis #React2Shell

Keypoints

  • Hackers announced the intrusion on a cybercrime forum and attempted extortion but reportedly failed.
  • LexisNexis says the compromised servers mostly contained legacy and deprecated data from before 2020.
  • Confirmed compromised items include customer names, user IDs, business contact details, respondent IPs, and support tickets.
  • The threat actor claimed to have obtained millions of records, employee credentials, software development secrets, and personal data on about 400,000 people, including over 100 .gov addresses.
  • LexisNexis states the matter is contained with no evidence of impact to its products and services, and this follows prior related breaches.

Read More: https://www.securityweek.com/new-lexisnexis-data-breach-confirmed-after-hackers-leak-files/