{
  "id": 9361143,
  "title": "Academic publisher Elsevier hit by LAPSUS$ redirect attack",
  "url": "https://urgent.news/2026/09/23/academic-publisher-elsevier-hit-by-lapsus-redirect-attack-9361143",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-23T15:08:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/23/academic-publisher-elsevier-hit-by-lapsus-redirect-attack/5298592"
  },
  "original_language": "en",
  "account": "Academic publisher Elsevier announced it had been targeted by the cybercriminal group LAPSUS$ on September 21, as students discovered its platform redirecting users to a leak page. A nursing student shared their experience on Reddit, noting that the issue occurred whenever they attempted to access \"homework and textbooks\" on the Elsevier website. Elsevier, headquartered in Amsterdam, stated that they identified the compromise on the same day and quickly resolved the issue, restoring normal service. The cybersecurity team concluded that the attack was narrowly scoped and short-lived, affecting only certain web properties and not core platforms, customer data, research content, or operational systems. Despite the incident, Elsevier did not disclose which specific platforms were impacted or for how long the LAPSUS$ redirect was active. Elsevier is renowned for its ScienceDirect platform, which provides access to scientific, technical, and medical journal articles, as well as ClinicalKey, an AI-driven platform for medical professionals, and LeapSpace, an AI-assisted workspace for academic researchers. LAPSUS$ is infamous for its high-profile cyberattacks on major companies like Rockstar Games, Adidas, GitHub, BT, Microsoft, Okta, Samsung, and Vodafone, among others. The group was most active between 2020 and 2022, resurfacing in 2025 in partnership with other cybercrime groups.",
  "summary": "Customers got crime crew's calling card instead of access to journals",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Academic publisher Elsevier hit by LAPSUS$ redirect attack",
        "url": "https://urgent.news/2026/09/23/academic-publisher-elsevier-hit-by-lapsus-redirect-attack",
        "published": "2026-09-23T15:08:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}