Academic publisher Elsevier hit by LAPSUS$ redirect attack
Elsevier says a short-lived LAPSUS$ compromise redirected some visitors to a criminal leak page.
Elsevier confirmed that on September 21 visitors to some of its platforms were redirected to a LAPSUS$ leak page. The Amsterdam-based publisher said the compromise was narrowly scoped and brief, and that core platforms, customer data, research content, and operational systems were not compromised. Students reported the redirect on September 22 while trying to reach journals and textbooks. Elsevier operates ScienceDirect, ClinicalKey, and LeapSpace; it did not name the affected properties.