LexisNexis took three of its services offline last week after detecting suspicious activity on servers managed by a third-party vendor [1], [2].

The outage affects tools used for deep-dive research and data retrieval, highlighting the vulnerability of major data providers to security lapses within their supply chains.

The company disabled its Diligence, Metabase API, and Newsdesk services [1], [2]. These three services were taken offline as a precautionary measure once the unusual activity was identified [1], [2].

According to reports, the affected servers were hosted and managed by an unnamed third-party provider [1], [2]. The company has not yet disclosed the nature of the activity or whether a data breach occurred.

LexisNexis has not provided a timeline for when the services will return to full operation. The company said the shutdown was necessary to ensure the integrity of its systems following the detection of the unusual server behavior [2].

Security analysts note that reliance on third-party infrastructure often creates blind spots for companies. When a vendor's environment is compromised, the primary company may be forced to shut down healthy services to prevent further lateral movement by an attacker, a move that disrupts business but protects data.

LexisNexis took three of its services offline last week after detecting suspicious activity.

This incident underscores the systemic risk of third-party dependency in the data services industry. By relying on an unnamed vendor for hosting, LexisNexis experienced a service disruption that it could not immediately resolve internally. This event demonstrates how a security event at a single infrastructure provider can ripple upward, forcing a global data company to disable critical APIs and research tools to mitigate unknown risks.