Academic publisher Elsevier hit by LAPSUS$ redirect attack
Customers got crime crew's calling card instead of access to journals
Elsevier, the leading academic publisher, confirmed on September 22 that its platform was compromised by cybercriminals affiliated with the LAPSUS$ group. A nursing student posted a screenshot on Reddit showcasing how Elsevier's website redirected users to LAPSUS$'s leak site whenever they attempted to access textbooks or homework materials.
While the Amsterdam-based company stated that the incident was "narrowly scoped" and did not affect core platforms, customer data, research content, or operational systems, they did not disclose the specific platforms impacted or the duration of the attack. LAPSUS$, known for targeting high-profile companies such as Rockstar Games, Adidas, GitHub, BT, Microsoft, Okta, Samsung, and Vodafone, has a history of conducting large-scale cyberattacks.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Academic publisher Elsevier hit by LAPSUS$ redirect attack theregister.com