Cyber Shenanigans: Elsevier’s Blunder
The academic publishing titan Elsevier found itself in quite a jam this week when students stumbled upon its platform being diverted to a cybercriminal group’s leak page. A distressed nursing student took to Reddit on September 22, posting an image of LAPSUS$’s leak site instead of their essential “homework and textbooks.” “Every time I attempt to access the Elsevier website, I encounter this,” they lamented. “Does anyone have any insights or explanations? Completely unsettling.”
The Quick Resolution
Headquartered in Amsterdam, Elsevier engaged in a conversation with GadgetLad, downplaying the incident’s impact. “On September 21, Elsevier recognized that users of certain platforms were being directed to a third-party site,” remarked a spokesperson, likely maintaining a composed demeanor. “Our cybersecurity team acted promptly, rectifying the problem and restoring regular service.” The cyber team believes it was a brief incident, a mischievous rerouting of traffic on some of their sites. Fortunately, no essential platforms, user data, or research materials were compromised.
Keeping It Under Wraps
Elsevier remained tight-lipped about additional specifics regarding which platforms were affected or the duration of this digital disruption. The company is famous for its ScienceDirect platform, a rich source of scientific, technical, and medical journal articles. It also features ClinicalKey, an AI-enhanced platform for swift medical inquiries, and LeapSpace, an AI-supported haven for academic scholars.
The Notorious LAPSUS$ Group
LAPSUS$, these audacious individuals are well-acquainted with trouble, making news with their cyber antics against major players like Rockstar Games, leading to the infamous Grand Theft Auto VI leaks. Their recent escapades include Adidas and GitHub, among other mischievous acts when they thrived between 2020 and 2022. Their exploits prompted BT, Microsoft, Okta, Samsung, and Vodafone to stay vigilant, resulting in law enforcement apprehending the teenagers.
The Comeback of LAPSUS$
After a hiatus, the LAPSUS$ name reemerged in 2025, collaborating with Scattered Spider and ShinyHunters in new cyberattacks aimed at well-known brands. However, by then, it had diminished to about six attacks per month, according to SOCRadar.
Details Unveiled
Elsevier’s digital diversion was a minor incident, swiftly managed before it gained widespread attention. LAPSUS$, once maestros of cyber mischief, appear to have calmed down, but their enduring digital footprint keeps the online community vigilant.
“When Academic Platforms Go Cyber Clubbing”
So there you have it. Elsevier’s brief cyber excursion prompted by LAPSUS$ was resolved quickly. Stay watchful of your digital resources, everyone. You never know when you might find yourself in an unforeseen situation. Cheers!