LexisNexis Risk Solutions breach on GitHub exposed data of 364,000 people

Organization
LexisNexis Risk Solutions
Exploit
Credential Compromise
Industry
Business Services

LexisNexis Risk Solutions, a data broker and risk analytics firm, began notifying more than 364,000 people in late May 2025 that their personal information had been taken in a breach dating back to Christmas Day 2024.

The company said the data had not been held on its own network. It sat on GitHub, the third party platform LexisNexis Risk Solutions used for software development, and an unknown attacker reached it through a compromised company account. The firm said it learned of the problem on 1 April 2025, when an unknown third party contacted it claiming to have obtained the information.

According to notification letters filed with state regulators, the exposed fields varied by individual and could include name, postal address, email address, telephone number, date of birth, Social Security number and driver's licence number. The Record reported that filings were lodged in Maine, South Carolina and Vermont, and that the company said it had found no evidence of further misuse of the data.

LexisNexis Risk Solutions offered affected individuals two years of identity protection services and said it had engaged outside cybersecurity specialists and was working with law enforcement. A company spokesperson confirmed the incident to TechCrunch but would not say whether a ransom demand had been made. The company maintained throughout that its own systems and products were never compromised.

Sources