LexisNexis Risk Solutions has disclosed that a security breach in December 2024 resulted in the theft of personal data belonging to more than 364,000 individuals. The Georgia-based data analytics company began notifying affected individuals on May 24th about the incident.
According to the company’s notification letters, LexisNexis learned on April 1, 2025, that an unauthorized third party had acquired company data from GitHub, a third-party platform used for software development. The breach occurred on December 25, 2024, when attackers used a compromised company account to access and steal data.
“Our Information Security team, in consultation with a forensic firm, immediately began investigating and confirmed that some data which was held in GitHub was acquired by an unknown third party,” a LexisNexis spokesperson stated. The company emphasized that the breach did not affect LexisNexis’s own networks or systems.
In a filing with the Maine Attorney General’s Office, LexisNexis revealed that 364,333 individuals were impacted. The exposed personal information included:
– Names
– Contact information (phone numbers, postal or email addresses)
– Social Security numbers
– Driver’s license numbers
– Dates of birth
The company assured that no financial information, credit card details, or other sensitive personal data was compromised in the breach.
LexisNexis is providing affected individuals with two years of free identity protection and credit monitoring services. The company has also advised victims to monitor their account statements and credit reports for potential fraud or identity theft attempts.
As a subsidiary of British multinational data analytics provider RELX, LexisNexis operates in over 180 countries and territories with offices in 40 countries. The company employs more than 11,800 people worldwide and serves 85% of Fortune 500 companies, including nine of the world’s top 10 banks.
