Elsevier domains and clinical/education platforms redirected to LAPSUS$ 'Chapter II' extortion pages
On September 21, 2026, multiple Elsevier domains and education/clinical platforms redirected for at least 78 minutes to LAPSUS$ extortion pages taunting the FBI; Elsevier calls the compromise narrowly scoped, while researchers tie the campaign to hijacked…
On September 21, 2026, visitors to several Elsevier web properties were redirected to a page branded 'LAPSUS$ GROUP, Chapter II,' which carried a signed statement mocking the FBI and a countdown to a future victim. Cloudscope researchers say three domains — elsevier.com, evolve.elsevier.com, and submit.elsevier.com — redirected for at least 78 minutes, from around 7:49pm CT until before 10:09pm CT, likely due to a changed DNS record, CDN redirect rule, or compromised management account; a Chinese forum post claiming altered Cloudflare redirect rules could not be verified. Separately, Sorami Consulting reported that connections to Elsevier Evolve, Sherpath, and ClinicalPharmacology, as well as GSDD APIs, were redirected in the same campaign to extortion splash pages hosted on domains including lapsus.ar.io and lapsus.bz. Elsevier confirmed the incident on September 21, describing the compromise as narrowly scoped and brief, and said core platforms, customer data, research content, and operational systems were not compromised; the company did not name the affected properties or an official duration, so the affected-domain and timing figures come from researchers rather than the company, and Elsevier has not explained the cause or addressed possible credential theft. Public discussion described nursing and medical students locked out of exams and simulation charting, and students reported the redirect on September 22 while trying to reach journals and textbooks. Elsevier, based in Amsterdam and operator of ScienceDirect, ClinicalKey, and LeapSpace, did not specify which platforms were involved. Securonix found no evidence of personnel continuity with the original 2021-2022 LAPSUS$ cluster, though a 2026 LAPSUS$-branded leak site has named Virta Health, Vodafone Germany, and AYA Bank.
- Redirects occurred September 21, 2026, to a page branded 'LAPSUS$ GROUP, Chapter II' with a statement taunting the FBI and a countdown to a future victim.
- Cloudscope: elsevier.com, evolve.elsevier.com, and submit.elsevier.com redirected for at least 78 minutes, from roughly 7:49pm CT until before 10:09pm CT.
- Suspected causes per Cloudscope: a DNS record change, CDN redirect rule, or compromised management account; a Chinese forum claim of altered Cloudflare redirect rules is unverified.
- Sorami Consulting: connections to Elsevier Evolve, Sherpath, and ClinicalPharmacology, plus GSDD APIs, redirected to LAPSUS$ extortion splash pages on domains including lapsus.ar.io and lapsus.bz.
- Elsevier confirmed the incident, calling it narrowly scoped and brief, and said core platforms, customer data, research content, and operational systems were not compromised.
- Elsevier did not name the affected properties, an official duration, or a cause, and has not addressed possible credential theft; timing and affected-domain details come from researcher reports, which diverge from each other on which…
- Impact reported by users: nursing and medical students locked out of exams and simulation charting; students hit the redirect on September 22 while trying to reach journals and textbooks.
- Elsevier is Amsterdam-based and operates ScienceDirect, ClinicalKey, and LeapSpace.
Coverage timelineoldest first · each row is one article
- · 4d agoBrief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
Help Net Security· 72
Three Elsevier domains, including manuscript portal submit.elsevier.com, redirected for 78 minutes to a LAPSUS$ extortion page taunting the FBI.
- · 4d agoElsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect Campaign
DataBreaches.net· 75
LAPSUS$ hijacked Elsevier education and clinical APIs, redirecting users to extortion splash pages.
- · 3d agoAcademic publisher Elsevier hit by LAPSUS$ redirect attack
The Register · Security· 62