Academic publisher Elsevier has confirmed a short-lived compromise after visitors to its platforms were bounced to a cybercriminal crew’s leak page.
The problem surfaced on Reddit on September 22, when a nursing student posted a screenshot of the LAPSUS$ leak site after trying to reach homework and textbook material.
An Elsevier spokesperson told The Register that on September 21 the company spotted visitors to select platforms being redirected to a third-party page. Its security team resolved the issue and restored service. The company described the event as narrowly scoped and limited in duration, adding that it found no sign that core platforms, customer data, research content or operational systems were affected.
Elsevier did not answer follow-up questions about which platforms were hit or how long the redirect stayed in place. The Amsterdam-based firm runs ScienceDirect, the ClinicalKey clinical reference tool and LeapSpace, an AI workspace for researchers.
LAPSUS$ built its reputation on loud intrusions between 2020 and 2022. The crew leaked early Grand Theft Auto VI material after breaching Rockstar Games, and its victim list grew to include Microsoft, Okta, Samsung, Nvidia, BT and Vodafone. Those attacks drew a coordinated law enforcement push against the teenagers behind the group.
The redirect is a reminder that even mature publishers depend on web infrastructure that can be turned against their own users.
