Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
Three Elsevier domains, including manuscript portal submit.elsevier.com, redirected for 78 minutes to a LAPSUS$ extortion page taunting the FBI.
On September 21, 2026, elsevier.com, evolve.elsevier.com and submit.elsevier.com redirected to a page branded 'LAPSUS$ GROUP, Chapter II' carrying a signed statement mocking the FBI and counting down to a future victim. Cloudscope researchers say the redirect ran at least 78 minutes (7:49pm to before 10:09pm CT) and was likely caused by a DNS record, CDN redirect rule, or management-account change; a Chinese forum post claiming altered Cloudflare redirect rules could not be verified. Elsevier has offered no explanation or statement on possible credential theft. Securonix found no evidence of personnel continuity with the original 2021-2022 LAPSUS$ cluster, though a 2026 LAPSUS$-branded leak site named Virta Health, Vodafone Germany and AYA Bank.