
LexisNexis Risk Solutions, a major provider of legal, regulatory, and business information, experienced a massive data breach. The breach, which took place on December 25, 2024, was discovered on May 14, 2025, and has impacted a total of 364,333 individuals across the United States.
The breach involved a Distributed Denial of Service (DDoS) attack, which was claimed by a threat actor known as RipperSec. The cybersecurity incident exposed personally identifiable information (PII), including names, contact information, phone numbers, postal addresses, email addresses, Social Security numbers, driver’s license numbers, and dates of birth.
LexisNexis Risk Solutions reported the breach to the California, Maine, Montana, South Carolina, Texas and Vermont attorneys general. The company notified affected individuals via U.S. mail beginning May 27, 2025.
State-specific disclosures show that 28,933 Texans, 661 Mainers, 1,442 Montana residents, 4,770 South Carolinians and 6,222 Massachusetts residents were affected.
After discovering the breach, LexisNexis Risk Solutions began notifying affected individuals by U.S. mail and is taking steps to review security protocol.
If you received a notification from LexisNexis Risk Solutions, it is important to:








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)