RELX A.I CyberSecurity Scoring
RELX
Company Information
Website:http://www.relx.com
Employees number:2,681
Number of followers:107,690
NAICS:51
Industry Type:Technology, Information and Media
Homepage:relx.com
RELX Risk Score (AI oriented)
Between 750 and 799
RELXTechnology, Information and Media
Updated:
07/05/2026
07/05/2026
771/1000
Fair
Baa
RELX Global Score (TPRM)
xxxx
RELXTechnology, Information and Media
Score locked

RELXFair
Current Score
771Baa (FAIR)
01000
1 incidents
-49 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
768
MAY 2026
772
APRIL 2026
772
MARCH 2026
819
Breach
03 Mar 2026 • RELX
RELX Group and LexisNexis Legal & Professional: LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen
FulcrumSec Claims Breach of LexisNexis, Exposing 2GB of Sensitive Legal Data
770
CRITICAL-49
RELLEX1772562253
FulcrumSec Claims Breach of LexisNexis, Exposing 2GB of Sensitive Legal Data
On March 3, 2026, the threat actor FulcrumSec publicly took responsibility for a breach of LexisNexis Legal & Professional, a division of RELX Group, alleging the theft of 2.04 GB of structured data from the company’s AWS cloud infrastructure. The attack, which began on February 24, exploited the React2Shell vulnerability in an unpatched React frontend application a flaw reportedly left unaddressed for months.
FulcrumSec gained access via the compromised LawfirmsStoreECSTaskRole ECS task container, which had broad permissions, including read access to:
- Production Redshift data warehouse
- 17 VPC databases
- AWS Secrets Manager
- Qualtrics survey platform
The actor criticized LexisNexis’s security practices, highlighting that the RDS master password was set to "Lexis1234" and that a single task role had access to all AWS Secrets Manager entries, including production database credentials.
Exposed Data Includes:
- 3.9 million database records
- 400,000 cloud user profiles (names, emails, phone numbers, job functions)
- 21,042 enterprise customer accounts
- 45 employee password hashes
- 118 .gov email accounts (federal judges, DOJ attorneys, U.S. SEC staff, and court law clerks)
- 53 plaintext AWS Secrets Manager secrets
- Complete VPC infrastructure map
FulcrumSec clarified that this breach is unrelated to the December 2024 GitHub incident, where attackers stole Social Security numbers of 364,000 individuals via a third-party development platform. The repeated compromises raise concerns about systemic security gaps in one of the world’s largest legal data repositories.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
819
JANUARY 2026
819
DECEMBER 2025
819
NOVEMBER 2025
819
OCTOBER 2025
819
SEPTEMBER 2025
819
AUGUST 2025
819
JULY 2025
819
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for RELX ??
What was RELX's A.I Rankiteo Cyber Score in May 2026 ??
What was RELX's A.I Rankiteo Cyber Score in April 2026 ??
What was RELX's A.I Rankiteo Cyber Score in March 2026 ??
What was RELX's A.I Rankiteo Cyber Score in February 2026 ??
What was RELX's A.I Rankiteo Cyber Score in January 2026 ??
What was RELX's A.I Rankiteo Cyber Score in December 2025 ??
What was RELX's A.I Rankiteo Cyber Score in November 2025 ??
What was RELX's A.I Rankiteo Cyber Score in October 2025 ??
What was RELX's A.I Rankiteo Cyber Score in September 2025 ??
What was RELX's A.I Rankiteo Cyber Score in August 2025 ??
What was RELX's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on RELX's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with RELX ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view RELX's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?