Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
Elsevier’s main website and two portals were briefly redirected to a page branded “LAPSUS$ GROUP, Chapter II,” which included a taunting statement and a countdown to another alleged victim. Researchers say the incident likely involved a DNS or CDN edge change, but Elsevier has not yet explained how it happened or confirmed whether user data was exposed. #Elsevier #LAPSUS$

Keypoints

  • Three Elsevier domains were hijacked and redirected to a LAPSUS$-branded page.
  • The redirect lasted about 78 minutes before the domains were restored.
  • Affected portals included Elsevier.com, Evolve.elsevier.com, and Submit.elsevier.com.
  • Researchers suspect a DNS or CDN edge change caused the redirect.
  • LAPSUS$ appears to be reviving its brand, though continuity with the original group is unconfirmed.

Read More: https://www.helpnetsecurity.com/2026/09/22/elsevier-domains-hijack-lapsus/