
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Elsevier has confirmed a brief compromise after students reported being redirected to a LAPSUS$ leak page. The publisher says core platforms, customer data and research content were not affected.
Academic publisher Elsevier has confirmed it was briefly compromised this week, after students found one of its platforms redirecting users to a leak page run by the LAPSUS$ cybercrime crew.
A Reddit user, a self-described nursing student, flagged the issue on September 22, posting a screenshot of the LAPSUS$ leak site after trying to reach "homework and textbooks." "Every time I try to open the Elsevier website, I am met with this," they wrote. "Anyone know anything? Totally creepy."
What happened
Amsterdam-based Elsevier told The Register it was briefly compromised following an attack on Monday but played down the wider impact. "On September 21, Elsevier identified that visitors to select platforms were being redirected to a third-party page," a spokesperson said. "Our cybersecurity team responded immediately, resolving the issue and restoring normal service."
The company called the incident narrowly scoped and limited in duration, and said there is no indication that core platforms, customer data, research content or operational systems were compromised. It did not answer follow-up questions about which platforms were affected or how long the redirect stayed live.
According to the security outlet Help Net Security, citing researchers at Cloudskope, three Elsevier domains were involved: Elsevier.com, the Evolve login and learning portal for nursing and health-professions education, and Submit.elsevier.com, where researchers upload manuscripts for peer review. The redirect ran for at least 78 minutes and sent visitors to a page branded "LAPSUS$ GROUP, Chapter II" that carried a signed statement taunting the FBI.
Why the target matters
Elsevier is best known for ScienceDirect, which hosts scientific, technical and medical journal articles. It also runs ClinicalKey, an AI-powered platform built to give medical professionals fast answers to care queries, and LeapSpace, an AI-assisted workspace for academic researchers — services used daily across hospitals and universities.
A familiar name returns
LAPSUS$ is better known for its criminal enterprises, including a high-profile attack on Rockstar Games that produced the earliest Grand Theft Auto VI leaks, and, more recently, attacks on Adidas and GitHub. The Rockstar intrusion was part of a wider spree between 2020 and 2022 that also hit BT, Microsoft, Okta, Samsung and Vodafone, triggering a coordinated law enforcement operation.
After a protracted break, the LAPSUS$ name returned in 2025, partnering with Scattered Spider and ShinyHunters for another string of attacks on household names, before the factions split up and activity dropped to a modest six attacks per month, according to SOCRadar.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.