Breach at data analytics firm impacts 364,000 people

Thursday, May 29, 2025
Hackers have nabbed LexisNexis data belonging to more than 360,000 people via GitHub.
Questionable timeline?
One security expert criticised the delay between the incident happening, LNRS being informed, and the subsequent disclosure.
Ilya Kolochenko, CEO at ImmuniWeb and a Fellow at the British Computer Society (BCS), said informing affected individuals in the wake of a breach should be of paramount importance to any organization.
"The timeline of the incident detection and disclosure is a bit surprising for a company offering legal and other comparatively sensitive services: the incident reportedly happened in December 2024, was detected in April 2025 after receiving information from the attackers, while disclosed only in May," Kolochenko said.
“Given that a lot of personal data was reportedly compromised, the incident detection and response timeline is pretty far from being perfect, to put it mildly."
That said, Kolochenko admitted that spotting such issues with partner platforms wasn't easy.
"Incidents stemming from compromised third-party repositories, like GitHub, are not trivial to detect and may even remain totally undetected," he said. Read Full Article
CPO Magazine: Legal Aid Data Breach Leaks Millions of Sensitive Records, MoJ’s Poor Cybersecurity Practices Slammed
CyberNews: Meta begins training AI using EU citizens’ data, but the fight’s not over yet