"Every time I try to open the Elsevier website, I am met with this," a self-described nursing student wrote on Reddit after finding Elsevier redirected to a LAPSUS$ leak page.
Elsevier confirms brief compromise
Amsterdam-based publisher Elsevier acknowledged a "brief" compromise after students discovered that some of its web traffic was being redirected to a cybercriminal group's leak page. The company told The Register that the event was identified on September 21 and that its cybersecurity team "responded immediately, resolving the issue and restoring normal service." Elsevier characterized the incident as "a narrowly scoped, limited-duration event" and said there is "no indication that core platforms, customer data, research content, or operational systems were compromised."
The redirect to LAPSUS$' leak page
The public first noticed the behavior on September 22 when a Reddit user, who identified themselves as a nursing student, posted a screenshot showing the Elsevier site redirecting to LAPSUS$'s leak page after attempting to reach "homework and textbooks." Elsevier confirmed that visitors to "select platforms were being redirected to a third-party page" and that normal service was subsequently restored. The company did not disclose which specific platforms were affected or how long the redirect persisted.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildLAPSUS$: return, partners, and recent tempo
The group behind the leak page, LAPSUS$, has a documented history of high-profile intrusions. The Register's report cites prior LAPSUS$ operations that included an attack on Rockstar Games that produced early Grand Theft Auto VI leaks, and more recent intrusions against Adidas and GitHub. Earlier victims named in coverage of the group's previous spree included BT, Microsoft, Okta, Samsung, and Vodafone, which prompted a concentrated law enforcement operation aimed at disrupting the teenage criminals behind those incidents.
After a prolonged pause, the LAPSUS$ name resurfaced in 2025. According to SOCRadar, the group partnered with Scattered Spider and ShinyHunters in another wave of attacks before splitting up; SOCRadar reported activity subsequently dropping to roughly six attacks per month.
How students and researchers experienced the incident
- Students: The visible symptom for at least one student was a redirect away from Elsevier content to LAPSUS$'s leak page when trying to access coursework and textbooks — a disruptive, confidence-eroding experience for learners who rely on publisher platforms for assignments.
- Researchers and clinicians: Elsevier platforms named in the report — ScienceDirect, ClinicalKey, and LeapSpace — serve distinct academic and clinical roles: ScienceDirect for scientific, technical and medical journal articles; ClinicalKey as an AI-powered tool for care queries; and LeapSpace as an AI-assisted workspace for researchers. Elsevier’s statement that "core platforms" and "research content" showed no indication of compromise is aimed squarely at calming concern among users of those services, though the company did not specify which web properties were involved in the redirect.
What this means for technologists, policymakers, and enterprises
- Technologists and security teams: Elsevier said its cybersecurity team "responded immediately" and restored normal service. For defenders, the incident underscores the need to monitor for traffic redirection and third‑party link integrity across public-facing properties, particularly where platforms integrate AI-powered or third-party components.
- Policymakers and regulators: The earlier concentrated law enforcement effort against LAPSUS$ highlighted in this account shows that criminal groups attract cross-jurisdictional response; the reappearance of the LAPSUS$ name in 2025 and its partnership activity reported by SOCRadar will be of interest to authorities tracking recidivist threat actors.
- Enterprises and procurement leaders: The episode reinforces the operational question raised by Elsevier's decision not to identify which "select platforms" were affected or the duration of the redirection — information that customers often seek after an incident to assess exposure and compliance implications.
Elsevier’s public posture — immediate remediation and no apparent compromise of core systems or data — aims to limit reputational and operational damage. Yet two concrete gaps remain in the record: the company declined to specify which platforms experienced redirects, and it did not say how long LAPSUS$'s page was in place. Given LAPSUS$'s documented history and its resurgence in 2025 alongside partners cited by SOCRadar, those are meaningful details for customers and investigators alike.
Link to original report: https://www.theregister.com/security/2026/09/23/academic-publisher-elsevier-hit-by-lapsus-redirect-attack/5298592




