LAPSUS$ Briefly Hijacks Elsevier's Academic Platform with Redirect Attack
Academic publishing giant Elsevier has confirmed it was briefly compromised this week after students and researchers reported being redirected from its platforms to a leak page belonging to the LAPSUS$ cybercrime group. One Reddit user, a nursing student trying to access study materials, posted a screenshot of the redirect on September 22, asking for an explanation.
Elsevier said the incident occurred on September 21 and affected 'select platforms', redirecting visitors to a third-party page before its security team resolved the issue. The company described the event as 'narrowly scoped' and of 'limited duration', stating there is no indication that core platforms, customer data, research content, or operational systems were compromised. Elsevier did not specify which platforms were affected or how long the redirect remained active. The company runs several widely used services, including ScienceDirect for scientific and medical journals, ClinicalKey for medical professionals, and LeapSpace for academic researchers.
LAPSUS$ has previously targeted major organisations including Rockstar Games, Microsoft, Okta, Samsung, Vodafone, Adidas, and GitHub, and was the subject of a significant law enforcement crackdown after its most active period between 2020 and 2022.