Urgent.News

What's breaking now, across thousands of outlets.

Science

Academic publisher Elsevier hit by LAPSUS$ redirect attack

Customers got crime crew's calling card instead of access to journals

Academic publisher Elsevier hit by LAPSUS$ redirect attack

Academic publisher Elsevier announced it had been targeted by the cybercriminal group LAPSUS$ on September 21, as students discovered its platform redirecting users to a leak page. A nursing student shared their experience on Reddit, noting that the issue occurred whenever they attempted to access "homework and textbooks" on the Elsevier website.

Elsevier, headquartered in Amsterdam, stated that they identified the compromise on the same day and quickly resolved the issue, restoring normal service. The cybersecurity team concluded that the attack was narrowly scoped and short-lived, affecting only certain web properties and not core platforms, customer data, research content, or operational systems.

Despite the incident, Elsevier did not disclose which specific platforms were impacted or for how long the LAPSUS$ redirect was active. Elsevier is renowned for its ScienceDirect platform, which provides access to scientific, technical, and medical journal articles, as well as ClinicalKey, an AI-driven platform for medical professionals, and LeapSpace, an AI-assisted workspace for academic researchers.

LAPSUS$ is infamous for its high-profile cyberattacks on major companies like Rockstar Games, Adidas, GitHub, BT, Microsoft, Okta, Samsung, and Vodafone, among others. The group was most active between 2020 and 2022, resurfacing in 2025 in partnership with other cybercrime groups.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Science

More from Wednesday 23 September →