Cloudskope researchers found three Elsevier properties briefly redirected on September 21 to a LAPSUS$ "Chapter II" page that taunted the FBI and counted down to a future victim. The affected sites were Elsevier.com, the Evolve login and learning portal, and the Submit manuscript portal, and the redirect lasted about 78 minutes before being cleared.
The likely break was at the edge, not inside the web apps: a DNS record, CDN redirect rule, or the account that controls them appears to have sent visitors to the fake page before they reached the real services. That means the incident could steer users away from a homepage, a login flow, and a manuscript-submission workflow without touching the origin servers.
Elsevier has not said how the redirect was changed or whether credentials or other data were taken. For organizations that front authentication or submission systems through Cloudflare, CDN rules, or DNS, the exposure sits in the trust layer that decides where users land, and that layer can matter even when the underlying portals still work.