databreaches.net 22 Sept 2026, 21:30 UTC

Elsevier Platforms Redirected Users to LAPSUS$ Extortion Pages

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

ON 21 September, Elsevier said visitors to selected platforms, including Evolve, Sherpath and ClinicalPharmacology, were redirected to a third-party page. Sorami Consulting reported that the redirects led to extortion pages associated with LAPSUS$, including domains such as `lapsus[.]ar[.]io` and `lapsus[.]bz`.

The report also claimed that production authentication endpoints for Elsevier and Gold Standard Drug Database services, including `api.gsdd.net/auth/AccessToken`, redirected token requests to attacker-controlled pages instead of returning access tokens. Users reportedly included nursing and medical students who were unable to access exams and simulation charting.

Elsevier disputed the broader characterisation of the incident. Its statement said the cybersecurity team responded immediately, resolved the issue and restored normal service. The company described the event as a “narrowly scoped, limited-duration” temporary redirection affecting certain web properties, and said there was no indication that core platforms, customer data, research content or operational systems had been compromised.

The supplied report does not establish whether the alleged API redirects resulted in stolen credentials or tokens, nor does it independently confirm LAPSUS$’s involvement. It also notes that LAPSUS$ has claimed to have returned under a “Chapter II” banner after previously announcing its permanent retirement.

View full article

Article by CyberSIXT