Academic publisher Elsevier hit by LAPSUS$ redirect attack

Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page.

One Reddit user, a self-described nursing student, highlighted the issue on September 22, posting a screenshot of LAPSUS$’s leak site after trying to access “homework and textbooks.”

“Every time I try to open the Elsevier website, I am met with this,” they wrote. “Anyone know anything or have any explanation? Totally creepy.”

Amsterdam-based Elsevier told it was briefly compromised following an attack Monday, but played down the wider impact.

“On September 21, Elsevier identified that visitors to select platforms were being redirected to a third-party page,” a spokesperson said. “Our cybersecurity team responded immediately, resolving the issue and restoring normal service.

“Our investigation indicates that this was a narrowly scoped, limited-duration event involving the temporary redirection of traffic for certain web properties. There is no indication that core platforms, customer data, research content, or operational systems were compromised.”

Elsevier did not respond to additional questions related to the specific platforms that were affected or for how long LAPSUS$’ redirect was in place.

The company is best known for its ScienceDirect platform, which hosts scientific, technical, and medical journal articles.

It is also behind ClinicalKey, an AI-powered platform designed to provide medical professionals fast answers to care queries, and LeapSpace – an AI-assisted workspace for academic researchers.

LAPSUS$, meanwhile, is better known for its criminal enterprises, namely big-name cyberattacks on the likes of Rockstar Games, which led to the earliest high-profile Grand Theft Auto VI leaks, and more recently, attacks on Adidas and GitHub.

The online assault on Rockstar Games was part of a wider spree of crimes carried out when the group was in its pomp between 2020 and 2022. 

Other victims included BT, Microsoft, Okta, Samsung, and Vodafone, which in turn stoked a concentrated law enforcement operation to disrupt the teenage criminals behind it.

After a protracted break, the LAPSUS$ name returned in 2025, partnering with Scattered Spider and ShinyHunters in another string of cyberattacks affecting household names, before splitting up and activity dropping to a modest six attacks per month, according to SOCRadar. ®

Original source Academic publisher Elsevier hit by LAPSUS$ redirect attack

Back to home