Academic publisher Elsevier hit by LAPSUS$ redirect attack
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Hacker groups and malware
- Lapsus$
- Reported by
- 1 outlet
security
Customers got crime crew's calling card instead of access to journals
Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page.
One Reddit user, a self-described nursing student, highlighted the issue on September 22, posting a screenshot of LAPSUS$’s leak site after trying to access “homework and textbooks.”
“Every time I try to open the Elsevier website, I am met with this,” they wrote. “Anyone know anything or have any explanation? Totally creepy.”
Amsterdam-based Elsevier told The Register it was briefly compromised following an attack Monday, but played down the wider impact.
“On September 21, Elsevier identified that visitors to select platforms were being redirected to a third-party page,” a spokesperson said. “Our cybersecurity team responded immediately, resolving the issue and restoring normal service.
“Our investigation indicates that this was a narrowly scoped, limited-duration event involving the temporary redirection of traffic for certain web properties. There is no indication that core platforms, customer data, research content, or operational systems were compromised.”
Elsevier did not respond to additional questions related to the specific platforms that were affected or for how long LAPSUS$’ redirect was in place.
The company is best known for its ScienceDirect platform, which hosts scientific, technical, and medical journal articles.
It is also behind ClinicalKey, an AI-powered platform designed to provide medical professionals fast answers to care queries, and LeapSpace – an AI-assisted workspace for academic researchers.
LAPSUS$, meanwhile, is better known for its criminal enterprises, namely big-name cyberattacks on the likes of Rockstar Games, which led to the earliest high-profile Grand Theft Auto VI leaks, and more recently, attacks on Adidas and GitHub.
The online assault on Rockstar Games was part of a wider spree of crimes carried out when the group was in its pomp between 2020 and 2022.
Other victims included BT, Microsoft, Okta, Samsung, and Vodafone, which in turn stoked a concentrated law enforcement operation to disrupt the teenage criminals behind it.
After a protracted break, the LAPSUS$ name returned in 2025, partnering with Scattered Spider and ShinyHunters in another string of cyberattacks affecting household names, before splitting up and activity dropping to a modest six attacks per month, according to SOCRadar. ®
Originally published by The Register. © The Register.
Fastnexa security experts
Worried Lapsus$ could come after your company?
We test your defences the way groups like Lapsus$ actually break in, then help you close the gaps before they find them.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-23 15:08 UTC
Related stories
- [Virtual Event] Cybersecurity Outlook 2027
Dark Reading · 2026-12-03
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · 2026-11-12
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · 2026-10-08
- AI Agents Are Privileged Users; Who Is Auditing Their Access?
Dark Reading · 2026-09-28
- IAM for AI agents: A Practical Enterprise Framework
The Hacker News · 2026-09-28