Cyberattack at LexisNexis Risk Solutions

December 29, 2025

INCIDENT

Risk management provider, LexisNexis Risk Solutions (LNRS) suffered a cyberattack where personally identifiable information for over 360,000 customers ended up stolen.
“On April 1, 2025, we learned that on December 25, 2024, an unauthorized third party acquired certain LNRS data from a third-party platform used for software development,” the company said in a letter to victims. “The issue did not affect LNRS’s own networks or systems.
Based on LNRS’ review of the impacted data, the Alpharetta, Georgia-based company determined personal information ended up affected in the attack. There were 364,333 people affected in the attack.

Incident Date

December 25, 2024

Estimated Cost

Unknown at this time

Type of Malware

No Malware identified

Threat Source

No threat source identified