Threats · 5h ago
Cloudskope researchers found three Elsevier properties briefly redirected on September 21 to a LAPSUS$ "Chapter II" page that taunted the FBI and counted down to a future victim. The affected sites were Elsevier.com, the Evolve login and learning portal, and the Submit manuscript portal, and the redirect lasted about 78 minutes before being cleared.
The likely break was at the edge, not inside the web apps: a DNS record, CDN redirect rule, or the account that controls them appears to have sent visitors to the fake page before they reached the real services. That means the incident could steer users away from a homepage, a login flow, and a manuscript-submission workflow without touching the origin servers.
Elsevier has not said how the redirect was changed or whether credentials or other data were taken. For organizations that front authentication or submission systems through Cloudflare, CDN rules, or DNS, the exposure sits in the trust layer that decides where users land, and that layer can matter even when the underlying portals still work.
2 sources covering this story
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Customers got crime crew's calling card instead of access to journals
Brief hijack makes Elsevier domains redirect to LAPSUS$ "Chapter II" page - Help Net Security
Three Elsevier domains have been redirecting users to a page branded "LAPSUS$ GROUP, Chapter II," counting down to a future victim.
Part of the PlainSec briefing for 2026-09-23