Elsevier Domains Hijacked: Redirected to LAPSUS$ ‘Chapter II’ Page

www.news4hackers.com-elsevier-domains-hijacked-redirected-to-lapsus-chapter-ii-page-elsevier-domains-hijacked-redirected-to-lapsus-chapter-ii-page

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

Incident Overview

Three domains associated with the Dutch academic publishing company Elsevier were temporarily redirected to a webpage attributed to the LAPSUS$ GROUP, featuring a statement signed by the group that mocked the FBI and outlined a countdown to an unspecified future target. According to Cloudskope researchers, the redirection occurred for at least 78 minutes, beginning around 7:49pm CT on September 21, 2026, and resolving before 10:09pm CT the same day.

Details of the Hijack

The affected domains included Elsevier.com, Evolve.elsevier.com, and Submit.elsevier.com, which serve as the company’s primary website, a learning management system, and a manuscript submission portal, respectively. Users accessing these domains were directed to a page displaying a message from the LAPSUS$ GROUP, which included a countdown mechanism and references to potential future targets.

Researchers from Cloudskope noted that the attack likely involved modifications to DNS records, CDN redirect rules, or account management settings. A post on a Chinese-language forum suggested the attacker altered Cloudflare’s redirect configurations, though this claim remains unverified.

LAPSUS$ Group Background

The LAPSUS$ GROUP, previously linked to extortion campaigns targeting major technology firms such as Microsoft, Okta, Nvidia, and Uber, was believed to have been inactive since late 2022 following law enforcement actions against several members. However, some former affiliates reportedly joined the Scattered Lapsus$ Hunters collective in 2025, continuing with high-profile data breaches and ransom demands.

Recent Activities

In 2026, a new LAPSUS$-branded leak site emerged, listing organizations including a U.S. healthcare provider, Vodafone Germany, and AYA Bank, among others. The group’s latest statement suggested plans to target a multinational corporation with over $50 billion in annual revenue, though the validity of these claims remains unconfirmed.

Related Security News

  • Researchers uncover malware that uses AI to choose its next move
  • The latest deepfake numbers give CISOs plenty to worry about
  • Simplify security management with CIS SecureSuite Platform
  • Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
  • Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

Conclusion

The incident highlights ongoing challenges in securing domain infrastructure and the potential for threat actors to exploit misconfigurations in DNS or CDN systems. Researchers uncover malware that uses AI to choose its next move Brief hijack makes Elsevier domains redirect to LAPSUS$ Chapter II page The latest deepfake numbers give CISOs plenty to worry about.



About Author

en_USEnglish