Academic publisher Elsevier hit by LAPSUS$ redirect attack

← Back to the feed

Academic publisher Elsevier hit by LAPSUS$ redirect attack

The Register · 27 minutes ago

Academic publisher Elsevier confirmed a cyberattack on 21 September, during which users attempting to access its platforms were redirected to a leak page operated by LAPSUS$, a notorious cybercriminal group. The incident was discovered by a nursing student who posted a screenshot on Reddit on 22 September, raising concerns about the security of a platform relied upon by students and academics worldwide. Whilst Elsevier claims the breach was brief and narrowly scoped, the attack demonstrates the continued threat posed by sophisticated cybercriminals to organisations holding valuable content.

Elsevier stated that its cybersecurity team resolved the issue and restored normal service, emphasising that there was no indication core platforms, customer data, or research content were compromised—only temporary traffic redirection on select web properties. The company hosts several major platforms including ScienceDirect (which contains scientific, technical, and medical journal articles), ClinicalKey (an AI-powered tool for medical professionals), and LeapSpace (an AI-assisted workspace for researchers). LAPSUS$ is responsible for major cyberattacks on Rockstar Games (leading to Grand Theft Auto VI leaks), as well as Adidas and GitHub; the group was particularly active between 2020 and 2022 but resurfaced in 2025 with reduced activity—currently conducting approximately six attacks per month.

  • Elsevier redirected to LAPSUS$ leak page on 21 September; issue resolved within hours.
  • Cybercriminal group responsible for high-profile attacks including Rockstar Games and GitHub.
  • Company says no core data compromised, only temporary redirect on select platforms.

Software

Read the full article at the source →