Academic publisher Elsevier hit by LAPSUS$ redirect attack

Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew’s leak page.

One Reddit user, a self-described nursing student, highlighted the issue on September 22, posting a screenshot of LAPSUS$’s leak site after trying to access “homework and textbooks.”

“Every time I try to open the Elsevier website, I am met with this,” they wrote. “Anyone know anything or have any explanation? Totally creepy.”

Amsterdam-based Elsevier told The Register it was briefly compromised following an attack Monday, but played down the wider impact.

“On September 21, Elsevier identified that visitors to select platforms were being redirected to a third-party page,” a spokesperson said. “Our cybersecurity team responded immediately, resolving the issue and restoring normal service.

Click here to read the full article

Skip to content