Skip to content
Elsevier Domains Hijacked by LAPSUS$ Group

Elsevier Domains Hijacked by LAPSUS$ Group

First seen 24 Sep 2026, 17:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 20:52 UTC
  • •Three Elsevier domains were hijacked for 78 minutes on September 21, 2026.
  • •The attack redirected users to a page taunting the FBI, with no data breach confirmed.
  • •Elsevier has not provided details on the attack vector or user data safety.

On September 21, 2026, three domains belonging to Elsevier were hijacked, redirecting users to a page branded 'LAPSUS$ GROUP, Chapter II' for at least 78 minutes. The affected domains included Elsevier.com, Evolve.elsevier.com, and Submit.elsevier.com, impacting nursing students and researchers. The attack method involved altering DNS or CDN settings, possibly through Cloudflare. Elsevier has not disclosed how the hijack occurred or if user data was compromised. The incident was confirmed by Cloudskope researchers and has since been resolved, with all domains now functioning normally. Despite the hijack, no ransomware was involved, and no data has been claimed by the attackers. The LAPSUS$ Group, known for extortion attacks, had been inactive since late 2022 but appears to be resurfacing.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-21
Elsevier domains hijacked
Three Elsevier domains redirected users to a LAPSUS$ page for 78 minutes, impacting nursing and research activities.
Help Net Security
2026-09-22
Cloudskope reports on hijack
Cloudskope confirmed the hijack and analyzed the attack method, suggesting DNS or CDN manipulation.
Cloudskope
2026-09-23
Elsevier responds
Elsevier acknowledged the incident and stated that their cybersecurity team resolved the issue promptly.
Help Net Security
2026-09-24
Current status update
All affected Elsevier domains are now operational, and no user data breach has been confirmed.
Cloudskope

More articles in this cluster (2)

Following this threat?

Track AYA Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed