Elsevier.com, Evolve and Manuscript Submission Redirected to LAPSUS$ for at Least 78 Minutes
Breach Summary
Updated September 22, 2026, 8:30pm CT. All Elsevier domains resolve normally; we re-checked tonight. Elsevier has now given its first public comment, a four-sentence statement to DataBreaches.net published at 12:30pm CT. It does not say how the redirect happened, when it began or ended, or what users who signed in during the window should do. Independent analysis has established that the page was staged three weeks in advance and that it delivered no payload.
Full analysis now published: Elsevier Was the Name on the Page. RELX Was the Pattern. connects the FBI's July warning on TeamPCP, the August arrests, the February breach of LexisNexis, and what RELX has told its shareholders about either.
For at least 78 minutes on the evening of September 21, Elsevier's own homepage served an extortion page. Typing www.elsevier.com landed visitors on a site branded LAPSUS$ GROUP, Chapter II, carrying a signed statement that taunted the FBI and counted down to a future victim. It was not a lookalike domain and not a phishing email. The real address went to the attacker's page.
Two other Elsevier properties did the same: submit.elsevier.com, where researchers upload manuscripts for peer review, and evolve.elsevier.com, the platform American nursing programs use for HESI exams and coursework. ScienceDirect was unaffected throughout.
This was not ransomware. Nothing was encrypted and no Elsevier data has been claimed by anyone. What is confirmed is narrower and, in one specific way, worse: for the length of that window, someone else controlled where Elsevier's traffic went.
What Happened
Elsevier is a Dutch academic publisher owned by RELX and one of the largest scientific publishers in the world. Almost nobody chooses to use it. Their university did, or their hospital did, or their nursing program did.
Who depends on the three affected domains
- Nursing students and programs. Evolve is where American nursing programs run HESI exams, Sherpath coursework, adaptive quizzing and post-exam remediation. A student who cannot reach Evolve cannot sit a required exam.
- Researchers submitting papers. submit.elsevier.com is the front door for manuscript submission to Elsevier journals.
- Everyone visiting the company itself. Customers, librarians, authors, job applicants, press.
The scale behind those domains
Elsevier does not publish a customer list, but its own reported figures give the scale. These are the company's numbers, not ours:
- 24,700+ institutions served across academic, industry and government
- ~3,000 journals, including The Lancet and Cell, accounting for roughly 18% of global research output
- 20+ million monthly unique visitors to ScienceDirect
- 5,500 hospitals and medical schools in 80+ countries using ClinicalKey
- 500,000+ course enrollments on Sherpath, the health-professions platform delivered through Evolve
- 4.5 million registered users of Complete Anatomy across 650+ medical schools
- 9,500 employees across 170+ countries
Those customers are universities, teaching hospitals, nursing schools, government research agencies and corporate R&D. Almost none can switch on short notice. Scopus, Elsevier's citation database, is what many institutions and governments use to decide which journals count toward tenure and funding.
How the evening unfolded (Central Time, September 21)
- ~7:49pm. A Chinese-language forum post reports submit.elsevier.com and Elsevier journal links redirecting to a LAPSUS$ domain, and claims the actor altered Elsevier's Cloudflare redirect rules.
- 7:57pm. A nursing student following an evolve.elsevier.com link lands on the LAPSUS$ page. Cloudskope has the screen recording.
- 8:17pm. Cloudskope confirms submit.elsevier.com and evolve.elsevier.com both redirect. sciencedirect.com loads normally.
- 8:29pm. www.elsevier.com also redirects.
- 8:33pm. Still live. This entry is published.
- 9:07pm. All three domains still return an HTTP 302 redirect to the LAPSUS$ page. No statement, no press coverage.
- 10:09pm. Redirect cleared. All three domains resolve normally. The reversal happened at some point between 9:07pm and 10:09pm and was not announced.
- September 22, 12:30pm. DataBreaches.net publishes a four-sentence statement from Elsevier, the company's first public comment. The same report relays a third-party claim that ClinicalPharmacology and the Gold Standard Drug Database authentication API were also redirected; see below.
- September 22, 8:30pm. Cloudskope re-checks all domains. Normal. No notice on the Elsevier press page or, per DataBreaches.net, on Evolve.
What visitors saw
A PGP-signed statement announcing the group's return from "retirement," taunting the FBI, and thanking another group, "TeamPCP," for providing "coverage." It listed Virta Health as a disclosed victim marked "Data Published," and ran a countdown to an unnamed upcoming target described as a global company with more than $50 billion in annual revenue. RELX's revenue is well below that figure, so the countdown most likely points elsewhere.
Elsevier's response
Nothing for roughly sixteen hours. Then, on September 22, a statement provided to DataBreaches.net and published at 12:30pm CT:
"On September 21, Elsevier identified that visitors to select platforms were being redirected to a third-party page. Our cybersecurity team responded immediately, resolving the issue and restoring normal service. Our investigation indicates that this was a narrowly scoped, limited-duration event involving the temporary redirection of traffic for certain web properties. There is no indication that core platforms, customer data, research content, or operational systems were compromised."
That is the entire public account. It gives no start time, no end time and no mechanism. It does not tell anyone who typed a password into an Elsevier login form during the window what to do. "No indication" describes what an investigation has not found; it says nothing about what the account that changed the routing was able to reach. As of this update there is no notice on Elsevier's press page or, per DataBreaches.net, on the Evolve site.
The open question is unchanged. A redirect that is quietly fixed and then described in four sentences leaves every affected student, author and institution unable to answer the only thing they need to know: whether the credentials they typed went somewhere they should not have.
Attack Vector Detail
Confirmed by direct observation
- www.elsevier.com, submit.elsevier.com and evolve.elsevier.com each returned an HTTP 302 redirect to an external page branded LAPSUS$.
- sciencedirect.com was unaffected at every check.
- The redirect was verified live at 8:17pm, 8:29pm, 8:33pm and 9:07pm CT on September 21, and found cleared at 10:09pm CT.
- The page named one prior victim, Virta Health, and that breach was real. Virta confirmed unauthorized access to a data repository in March 2026 and reported 14,636 affected individuals.
What independent analysis has since established
Securonix published a technical assessment of the "Chapter II" page on September 14, a week before the Elsevier redirect. Three findings from it matter here.
The page was staged weeks in advance. The Arweave name was leased on August 30, a small test object appeared shortly afterward, and the final 10,977-byte page was anchored on September 2. Elsevier's domains were pointed at infrastructure that had been sitting ready for nearly three weeks.
The page carried no payload. Securonix assessed it as "a static extortion announcement rather than a loader or payload-delivery page." Anyone who merely loaded the page during the window was not served malware.
The signature is real, but it does not identify anyone. The PGP signature validates against the published key, which confirms that whoever holds the private key signed the statement. Securonix holds low confidence that the operators are the original 2021-2022 crew, concluding that the evidence "supports continuity of persona and narrative more strongly than continuity of personnel."
That last point is a correction to the intuitive reading. The destination being an established LAPSUS$ leak site does not mean the original LAPSUS$ members did this. The brand may have been picked up by other operators.
Still unverified
- Whether any Elsevier data was taken. None has been claimed. Absence of a claim is not evidence of absence.
- How routing control was obtained. A Chinese-language forum post claims the actor altered Elsevier's Cloudflare redirect rules. We could not verify that.
- Who operated the page. The signature is cryptographically valid, but identity behind the key is unestablished.
- Whether the login pages collected anything. The destination page delivered no payload, but that does not address what happened to credentials typed into an Elsevier login form that had been pointed elsewhere. Only Elsevier can answer that.
- Exactly when and how the redirect was reversed. The clearing happened between 9:07pm and 10:09pm CT with no announcement. Elsevier's statement gives no times.
- Whether clinical drug-reference APIs were also redirected. DataBreaches.net relays a LinkedIn post by Sorami Consulting claiming that ClinicalPharmacology and the authentication endpoint of Elsevier's Gold Standard Drug Database, api.gsdd.net, were redirecting token requests during the window. We did not test those endpoints on September 21 and cannot confirm it. If accurate, the incident reached drug-information services used by hospital systems, not only publishing and education.
What the pattern indicates
This maps to MITRE ATT&CK T1584.001, Compromise Infrastructure: Domains, which covers hijacking a victim's domains or subdomains through registrar or DNS-provider account access. The usual precursor is T1078, Valid Accounts.
It was not DNS cache poisoning. Poisoning corrupts a resolver's cache and decays on TTL. This was authoritative and consistent across networks for the duration of the window.
Three properties spanning corporate, publishing and education failed together while ScienceDirect, hosted separately, did not. That points to a single compromised control plane rather than three separate intrusions, and it is consistent with a change at the DNS or CDN edge: a DNS record, a CDN redirect rule, or the account that manages them.
Cloudskope will not link to the extortion page or the archive it hosted.
Breach Pattern Timeline
The page Elsevier's domains pointed to did not appear that night. It was built, tested and published weeks earlier, and it sits at the end of a documented chain.
December 2021 to March 2022
LAPSUS$ surfaces with an extortion attack on Brazil's Ministry of Health, then runs a rapid series of intrusions at NVIDIA, Samsung, Vodafone, Microsoft and Okta. Microsoft tracks the group as DEV-0537 and documents its open recruitment of insiders. Extortion, not encryption, is the model throughout.
Late March 2022
Arrests in the United Kingdom and Brazil. City of London Police confirm at least two of those charged are teenagers. Public activity largely stops.
March 23, 2026
LAPSUS$ lists Virta Health on its leak site. Virta detects unauthorized activity the following day and later confirms files were potentially accessed between March 19 and March 22, reporting 14,636 affected individuals.
July 2, 2026
The FBI issues FLASH-20260702-01 on TeamPCP, describing large-scale software supply chain compromises through Trivy, KICS, LiteLLM, the Telnyx Python SDK, and the npm and PyPI registries. The Bureau states the group extracted "cloud access tokens, credentials, API keys, and other authentication material associated with services such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure." Its first recommendation is to rotate cloud credentials and publishing tokens.
August 26 and 27, 2026
Two alleged TeamPCP members are arrested in Western Australia, facing 14 cybercrime charges between them. One is denied bail; the other's lawyer does not apply for it.
August 30 to September 2, 2026
The Arweave name later used for the "Chapter II" page is leased on August 30. A small test object follows. The final page is anchored on September 2.
September 10, 2026
Dataminr publishes an intelligence brief on the group's return, documenting the statement, the countdown, and a relationship in which TeamPCP's cloud compromises have fed victim access into LAPSUS$-branded extortion operations.
September 14, 2026
Securonix publishes a technical assessment: the PGP signature validates, the page is a static announcement with no payload, and personnel continuity with the original LAPSUS$ cluster is held at low confidence.
September 21, 2026
Three Elsevier domains redirect to that page for at least 78 minutes. The redirect is cleared the same night without announcement.
September 22, 2026
Help Net Security reports the redirect in the morning. At 12:30pm CT, DataBreaches.net publishes Elsevier's first statement: a "narrowly scoped, limited-duration event," with "no indication" of compromise to core platforms, customer data, research content or operational systems. No cause, no times, no guidance to users.
What the statement appears to say about the arrests
The page thanks TeamPCP: "your sacrifice provided us with the exact coverage we needed. We owe you all our gratitude for falling and taking on the acts of our cooperation." Read against the August arrests, that is a claim that the prosecution of TeamPCP absorbed attribution for work the two groups did together. Securonix assesses an operational connection between them at moderate confidence.
The inference, stated as an inference
A federal advisory says TeamPCP harvested cloud credentials and API keys at scale. Threat intelligence reporting says TeamPCP access has fed LAPSUS$-branded operations. Elsevier's edge routing changed without any software vulnerability being involved. Those three facts are consistent with stolen edge credentials being used months after they were taken. They do not establish it, and no public evidence ties the Elsevier change to any specific credential. We are stating the hypothesis plainly rather than implying it.
The full chain, sourced document by document, is laid out in Elsevier Was the Name on the Page. RELX Was the Pattern.
Executive Lessons
It remains too early to state a cause. Elsevier's only statement names none, and nobody outside its incident response team knows whether this was a single stolen credential or the visible edge of something larger. What follows are the questions that decide which, not conclusions.
- How was routing control obtained? DNS, CDN and registrar management accounts are among the most privileged credentials an organization holds, and among the least monitored. Were they behind phishing-resistant MFA, and is there an audit trail of the change?
- Was the credential recently rotated? The FBI's July 2026 FLASH on TeamPCP told organizations to rotate cloud tokens and API keys after a supply chain campaign that harvested exactly that material. Any company that did not act on that notice should check whether its edge credentials were in scope.
- Was the edge the whole of it? A redirect can be the entire incident or the only visible part of one. That difference is not observable from outside.
- What did visitors send? Anyone attempting to sign in to Evolve or submit a manuscript during the window was interacting with a page under someone else's control. That question is owed to students, faculty and authors, and it is the one a silent fix leaves open.
The part worth generalizing
Nothing here required malware, an exploit, or a vulnerability in Elsevier's software. Whoever did this changed a setting. The control plane that decides where a company's name resolves sits outside most identity governance programs, outside most privileged access reviews, and frequently outside multi-factor authentication, because nobody classifies it as a system. It is the system that determines what the internet sees when it types your name.
Related Reading
Private Equity Implications
For sponsors holding publishing, edtech or information-services assets, this incident is a reminder that DNS, CDN and registrar accounts belong in the diligence scope. They are rarely inventoried, often held by a single administrator, and a single compromise can put an attacker's page on the company's primary domain within minutes.
How Cloudskope Can Help
Routing control is one of the highest-privilege assets any company owns and one of the least reviewed. Cloudskope's Cyber Risk Assessment covers DNS, CDN and registrar access alongside identity and third-party exposure.
For acquirers evaluating publishing and edtech targets, our M&A Cyber & IT Due Diligence puts edge infrastructure in scope.
Frequently Asked Questions
Is Elsevier down?
No. The redirect was cleared and all Elsevier domains resolve normally as of 10:09pm CT on September 21, 2026. Between roughly 7:49pm and some point before 10:09pm CT, www.elsevier.com, evolve.elsevier.com and submit.elsevier.com redirected visitors to an external page branded LAPSUS$. ScienceDirect was never affected.
Has Elsevier said anything?
One statement, provided to DataBreaches.net and published September 22 at 12:30pm CT. Elsevier called it "a narrowly scoped, limited-duration event involving the temporary redirection of traffic for certain web properties" and said there is "no indication that core platforms, customer data, research content, or operational systems were compromised." The statement does not say how the redirect happened, when it started or ended, or whether users who signed in during the window should reset their passwords. There is no notice on Elsevier's press page.
Is Sherpath hacked?
Sherpath itself was not hacked, on the available evidence. Sherpath is reached through evolve.elsevier.com, and that address redirected to an attacker-controlled page during the window. No coursework, grades or HESI results have been claimed by anyone. Students who signed in during the window should change their Evolve password and any password reused elsewhere. A fuller answer for students is here: Is Sherpath Hacked?
Is Evolve hacked?
The Evolve platform was not shown to be compromised. Its web address redirected elsewhere for roughly two hours. That is a meaningful difference: the systems holding student records were not demonstrated to be touched, but anyone who entered credentials during the window sent them to a page the attacker controlled.
Was this ransomware?
No, on the available evidence. Nothing was encrypted and no ransom demand against Elsevier has been published. The incident was a redirect of Elsevier's web traffic to an attacker-controlled page, which points to the DNS or CDN layer rather than to the systems holding Elsevier's data.
Was Elsevier customer or student data stolen?
No data theft has been claimed or confirmed. That is not the same as confirmation that nothing was taken. Only Elsevier, with visibility into its own environment, can answer that.
I tried to log in to Evolve during the outage. What should I do?
If you entered your username and password on any Elsevier page during the redirect window, change that password, and change it anywhere else you reused it. Enable multi-factor authentication if your institution offers it. Watch for phishing emails referencing your Evolve or HESI account over the coming weeks.
What kind of attack was this?
It matches MITRE ATT&CK T1584.001, Compromise Infrastructure: Domains, which covers hijacking a victim's domains through registrar or DNS-provider account access. It was not DNS cache poisoning, which corrupts a resolver's cache temporarily and decays on TTL.
Who is LAPSUS$?
An extortion group that first appeared in December 2021 with an attack on Brazil's Ministry of Health and went on to breach NVIDIA, Samsung, Vodafone, Microsoft and Okta in 2022. It is known for social engineering, SIM swapping and recruiting insiders rather than deploying malware. Several members were arrested in the UK and Brazil in 2022. The group claimed a breach of Virta Health in March 2026.
How many customers does Elsevier have?
Elsevier reports serving more than 24,700 academic, industry and government institutions, publishing roughly 3,000 journals, and reaching over 20 million monthly unique visitors on ScienceDirect. Its ClinicalKey platform is used by around 5,500 hospitals and medical schools in more than 80 countries.
.png)