Executive Risk & Board Advisory

Elsevier Was the Name on the Page. RELX Was the Pattern.

Blog Meta Icon
Dipan Mann
Founder, CEO & CTO
Blog Meta Icon
September 22, 2026
Blog Meta Icon
35 min read
Blog Main Image

The page had been sitting on Arweave since September 2. The FBI had described the credentials in July. Elsevier's sister company had been breached by the same network in February. Nobody at RELX has said a word about any of it.


UPDATE, SEPTEMBER 22, 2026 (AFTERNOON)

Help Net Security has reported the redirect, citing this firm's observations alongside the Securonix analysis of the destination page. Editor-in-chief Zeljka Zorz writes that Elsevier "is yet to offer an explanation on how it happened or say whether users should worry about their login credentials or other data having been stolen," and that Help Net has put questions to the company. As of this update, more than 20 hours after the redirect was reversed, Elsevier's press page carries a new research announcement about maternal sleep and childhood obesity, dated today, and nothing about the incident.


7:57 PM Central

On the evening of Sunday, September 21, 2026, a nursing student in Wisconsin was working through Sherpath assignments due that night when the page refreshed itself and would not come back. Sherpath is Elsevier's nursing coursework platform. Students reach it through evolve.elsevier.com, the sign-in door that also serves HESI, EAQ, SimChart and Shadow Health, the platforms through which American nursing programs deliver coursework, administer exams and run post-exam remediation. Elsevier reports more than 500,000 course enrollments on Sherpath alone. She did what students do: cleared her cache, restarted an aging laptop, tried again, and got a "connection unstable" page. Then she called her boyfriend, Hudson LePine, a cybersecurity analyst at Cloudskope. When they followed Elsevier's own link, what loaded was a black page with a red border, titled LAPSUS$ GROUP, carrying a PGP-signed statement that taunted the FBI and a countdown clock to an unnamed victim.

Her screen recording is timestamped 7:57 PM Central. The address bar in it reads lapsus.ar.io. The link she followed was Elsevier's.

Eight minutes earlier, at roughly 7:49 PM, a post on a Chinese-language technical forum had reported the same thing about submit.elsevier.com, the portal where researchers upload manuscripts for peer review, and claimed the actor had altered Elsevier's Cloudflare redirect rules. At 8:17 PM we confirmed both domains ourselves. At 8:29 PM, www.elsevier.com, the corporate homepage, followed. At 9:07 PM all three were still returning HTTP 302 redirects with a Location header of https://lapsus.ar.io/. At 10:09 PM they were clean. ScienceDirect, hosted on separate infrastructure, never wavered.

Elsevier did not announce the outage. It did not announce the fix. It has not said whether anyone who typed a password into an Elsevier login form during that window sent it somewhere Elsevier did not control. Its press office has, in the time since, issued a research announcement about sleep.

That is the incident as it was experienced. What follows is longer, because the incident is not the story. The story is where the page came from, who built it, what the FBI had already said in July about the class of credential most likely to have opened the door, what happened to Elsevier's sister company in February, and what RELX, the £9.6 billion parent of both, has chosen to tell its shareholders about any of it. Which is nothing.

What it looked like from a nursing program in Wisconsin

The student wrote up her evening for us the next day and said we could use it. We are not naming her. Her boyfriend is Hudson LePine, a cybersecurity analyst at this firm, which is how Cloudskope had a screen recording of Elsevier's front door pointing at an extortion page at 7:57 PM and was running its own checks on the domains by 8:17. We are saying so plainly because it explains our sourcing, and because a reader is entitled to know that the student in this piece is one degree from the firm writing it.

Her account is worth reading in full, because nothing Elsevier has published, which is nothing, describes what its customers experienced.

What was originally a productive evening stopped abruptly when Sherpath, the website I use for my nursing school homework modules, refreshed itself and refused to reload. It's not like I haven't had issues before, so I went down the checklist of clearing my cache and restarting my computer, but neither of those worked. I was still getting a "connection unstable" page. So, being luckier than most, I called up my personal IT guy, aka my boyfriend in cybersecurity, to see if he could help me get Sherpath to work, because I have assignments due tonight and exams rapidly approaching.

I didn't know what to think at first. I mean, it was sort of funny, because I guess there was no way my assignments were going to be done on time if the entire website is being held hostage. But after a little bit the reality started to sink in. Sherpath is directly tied to a lot of my school information. I have to use my school email to log into the website, and then I can either enter a password or get a code sent to my school email. Within Sherpath I have personal information set up under my account, and I also have personal data linked in Sherpath like my HESI exam scores.

If there's anything I've learned from the last two semesters, it's that my school information is not being protected the way it should be. This semester it's Elsevier. Last semester it was Canvas. What will next semester be, or the one after that? The school tells you not to click on random links, not to download unknown files, to change your passwords once a semester, to set up multi-factor authentication, never to share your passwords with anyone, and not to log into your accounts on untrusted wifi. Even with all of this, our data is not safe.

Three things in that account deserve more weight than they will get.

First, the login. Her Evolve account is keyed to her school email, and the second factor is a code sent to that same school email. That is the design at most programs. It means an Evolve credential is, in practice, a university credential, and a page that could have collected one could have collected the other. The Chapter II page collected nothing, on Securonix's analysis. The next page might.

Second, the HESI scores. HESI exams are the specialty and exit exams that predict performance on the NCLEX, the national licensing examination, and at many programs a passing HESI exit score is a graduation requirement. Those scores, and the personal information used to register for the exams, sit behind the door that was redirected. Nobody at Elsevier has said whether the account that changed the routing could reach them.

Third, Canvas. The same student sat finals on Canvas in May, when ShinyHunters redirected the platform at thousands of universities, and did homework on Sherpath in September, when Elsevier's domains went to LAPSUS$. Every piece of security advice her school has given her is about her own behavior. Neither incident involved her behavior. Both involved a vendor's credentials.

She also asked her classmates, in her cohort and the one above, what they made of it. The replies, as she recorded them: "I just saw that, I'm dying," with a laughing emoji. "Bruh I'm so screwed." "Are they going to change the due dates then??" "Girl I was already barely keeping up with everything, I swear if they don't change the due dates I'm going to fail." Her summary: "Almost every person I talked to didn't even think about what threats and negativities could come from Sherpath being hacked. They were only concerned with the immediate impacts on their studies."

That is the population Elsevier has chosen not to address. They are not reading Securonix. They are asking about due dates. The one piece of advice that reached this cohort on Sunday night, to change the password and change it everywhere it was reused, arrived because one student's boyfriend works at a security firm. Elsevier has had more than 24 hours to send the same sentence to half a million enrollments. It has not.

What we verified, and one thing the first report got wrong

Precision matters here because the record will be argued over. The forum post at 7:49 PM, and a second one on a related Chinese-language board, said the redirect went to lapsus.bz. Every check we ran returned a 302 to lapsus.ar.io. Whether lapsus.bz was an intermediate hop, a typo, or a domain that was later swapped, we cannot say. What we can say is that four independent checks over 50 minutes, from infrastructure the forum posters did not share, returned the same Location header, and that a nursing student's screen recording at 7:57 PM shows the same destination in her browser.

The forum post also claimed the mechanism: Cloudflare redirect rules. That claim is plausible, it is consistent with everything we observed, and we could not verify it. Elsevier could confirm or deny it in one sentence. It has done neither.

What the observations do establish is the shape. Three properties spanning corporate, publishing and education failed together, while a fourth on separate infrastructure did not. The failure mode was a redirect at the HTTP layer, not a defaced page served from Elsevier's own hosts. That pattern is the signature of a change at the DNS or CDN edge: a record, a rule, or the account that manages them. It is not the signature of an application exploit. Nobody found a bug in Evolve. Somebody changed where Evolve's name goes.

The page was built before anyone pointed Elsevier at it

Securonix ThreatWatch found lapsus.ar.io on September 9 and published a technical assessment on September 14, a full week before Elsevier's domains were redirected to it. The report, by analyst Dheeraj Kumar, reads like a construction log, and it is the single most important document for understanding what happened on the 21st.

The Arweave name was leased on August 30, paid for on Solana. A test object went up on August 30 or 31. The final page, 10,977 bytes, was anchored in Arweave block 1,992,730 at 15:01:42 UTC on September 2. The PGP signature on the statement carries a creation timestamp of 14:33 UTC the same day. Securonix independently validated that signature against the published key, fingerprint 7D0FA2E212E398576C797102131C4FF38C4D936B. The content hash is recorded. The gateway resolves to Hetzner (AS24940) behind a shared wildcard certificate that is not specific to this activity. The only external asset the page loads is a background image pulled from Wired's infrastructure.

What the page does not contain matters as much as what it does. Securonix found no fetch requests, no credential forms, no iframes, no redirects, no executable payloads. Their words: "a static extortion announcement rather than a loader or payload-delivery page." Anyone who merely loaded it was not served malware. The only MITRE technique Securonix could map to the page itself was T1583.006, acquiring web services infrastructure. No initial access, no execution, no persistence, no credential access, no impact. A billboard.

Read that against the Elsevier redirect and the division of labor becomes obvious. The page was one project, finished on September 2. The redirect was a second project, executed on September 21. The first required a wallet and a text editor. The second required a valid login to something that controls Elsevier's routing. Whoever did the second did not need to build anything. They needed a credential.

A page that cannot be taken down

One detail in the Securonix report deserves more attention than it has received. The page was not hosted on a bulletproof VPS or a Tor hidden service. It was written to Arweave, a blockchain-backed storage network designed so that data, once anchored, is permanent. The lapsus.ar.io name is an ArNS record, a naming layer on top of Arweave, purchased on Solana. The ar.io gateway that serves it is one of many; if that gateway goes away, the content does not.

That is a meaningful choice. Extortion sites live and die by takedowns: registrars suspend domains, hosts null-route servers, law enforcement seizes infrastructure, as they did with BreachForums in October 2025. A page anchored in Arweave block 1,992,730 has no registrar to lean on and no host to subpoena. It will still be there in a year.

So when Elsevier's domains were redirected, they were not pointed at a throwaway server that would be gone by morning. They were pointed at permanent, takedown-resistant infrastructure that had been sitting ready for 19 days. That is not an opportunist defacing a page they stumbled into. That is a prepared destination waiting for prepared access.

The countdown that reset

The countdown Securonix observed on September 9 was set for September 12 at 22:00 UTC and labeled "Chapter II First Victim Leak." WatchGuard's tracker records a leak in the U.S. healthcare sector on that date. By the time Elsevier's traffic arrived on September 21, the page showed Virta Health marked "Data Published" with a link to an archive on a bare IP, and a fresh countdown of roughly ten days to a second target described only as "a global company generating over $50 billion in annual revenue, with operations and a strong presence worldwide."

RELX reported £9,590 million in revenue for 2025, roughly $12 billion at current rates. Whatever the second target is, it is not Elsevier's parent, and the countdown on the page that Elsevier's visitors saw was never a countdown aimed at Elsevier. That is worth stating plainly, because the first reaction to a countdown on your own homepage is to assume it is about you.

So the sequence is this. The page was staged over three days in late August and early September. It ran its first leak on September 12. Nine days later, three Elsevier domains were pointed at it for at least 78 minutes, then pointed back. The redirect gave the page an audience it could not have bought: every researcher submitting a manuscript on a Sunday evening, every nursing student with a Monday exam, every visitor to the corporate front door of the company that publishes The Lancet.

The thank-you note

The signed statement on the page opens with gratitude to another group:

To TeamPCP, we send our sincere gratitude: your sacrifice provided us with the exact coverage we needed. We owe you all our gratitude for falling and taking on the acts of our cooperation.

On August 26, Australian Federal Police arrested two men in Western Australia in connection with TeamPCP. The AFP announced it on August 27. Ruben Ian Thomson, 21, of Cottesloe, and Michael Gaebler, 23, face 14 cybercrime charges between them. Thomson was denied bail. Both were due back in Perth Magistrates Court on September 18, three days before the Elsevier redirect.

Read against those arrests, the statement is not thanks for a successful operation. It is a claim that the prosecution of TeamPCP absorbed the attribution for work the two groups did together. "Taking on the acts of our cooperation" is a specific phrase. It says: what you were charged with, we did with you, and now you are carrying it. Securonix assesses the TeamPCP relationship at moderate confidence and interprets "falling" as a direct reference to the August 26 arrests. Dataminr's September 10 brief is more specific about the shape of the relationship: "TeamPCP's history involves cloud-native compromises of exposed control planes and developer ecosystems, which have previously supplied victim access to LAPSUS$-branded extortion campaigns."

Control planes. Developer ecosystems. Supplied victim access. Hold that thought, because the FBI had already written it down.

💡 Key Insight

Two RELX divisions were compromised in 2026 by actors in the same network. The company's half-year results, published between the two incidents, mention neither. Elsevier has not said a word.

What the FBI said on July 2

Eleven weeks before the redirect, the FBI issued FLASH-20260702-01 on TeamPCP. It is marked TLP:CLEAR, which means anyone could read it, forward it, or paste it into a ticket. It describes a group that injected malicious code into legitimate developer and security tools, named specifically as Trivy, KICS, LiteLLM and the Telnyx Python SDK, along with packages on npm and PyPI, and used that foothold to plant credential stealers and backdoors inside the CI/CD pipelines that build and deploy software at thousands of companies.

The Bureau named four malware families. CanisterWorm, which "harvests cloud tokens, credentials, and API keys from AWS, GCP, and Azure." SANDCLOCK, which extracts AWS credentials, Kubernetes tokens and environment variables. Mini Shai-Hulud, a self-replicating worm across npm and PyPI. Miasma, a cross-registry credential harvester. It listed 26 file hashes, six IP addresses, nine domains including scan.aquasecurtiy[.]org, a misspelling of Aqua Security, which maintains Trivy, and models.litellm[.]cloud, and four CVEs. One of the four is CVE-2025-55182, better known as React2Shell.

The first mitigation on the FBI's list: "Rotate all CI/CD secrets, tokens, and cloud credentials."

Read the list of what the malware takes and then read the list of what controls a company's edge routing. Cloudflare API tokens. Route 53 keys. Registrar logins. They are cloud credentials. They live in environment variables, in .env files, in the secrets stores that pipelines read from, in the memory of the runner that just deployed the marketing site. The FBI's malware list and the inventory of things that could redirect www.elsevier.com are the same list, read from opposite ends.

What 434,000 pipelines means

CloudSEK published its forensic accounting of the LiteLLM leg of the campaign on August 11, five weeks after the FBI notice and fifteen days before the arrests. It is the document that turns "TeamPCP harvested credentials" from a headline into a number, and the number is the reason this piece exists.

The chain, as CloudSEK reconstructs it, began at Trivy, the open-source vulnerability scanner that thousands of pipelines run on every build. "A leaked automation token, rotated but not fully revoked, left an approximately 20-day window in which the attacker force-pushed malicious code." Rotated but not fully revoked. Hold that phrase too. From Trivy the actor reached LiteLLM, the open-source gateway that companies use to route requests to OpenAI, Anthropic and other model providers, and pushed versions 1.82.7 and 1.82.8 to PyPI. The poisoned versions were live for roughly 40 minutes. That was enough.

The payload ran as a .pth file, which CloudSEK explains executes "at interpreter startup rather than on import," so "the payload ran wherever the package was merely installed, sidestepping the --ignore-scripts protection teams rely on." Once running, it took SSH keys, AWS, GCP and Azure credentials, Kubernetes tokens, .env files, LLM API keys, and CI/CD secrets, "including the values GitHub Actions tries to mask, scraped directly from /proc/<pid>/mem."

CloudSEK's exposure dataset covers more than 2,500 organizations and 434,000 CI/CD pipelines. The named entries read like an index fund. X Corp, 3,459 secrets. Fortum, the Finnish utility, 823. Krungthai Bank, 614. Deloitte, 462. Cisco, 327. Orange, 180. Vodafone Group, 83. London Stock Exchange Group, 48. Amazon Web Services, Samsung, Salesforce, Siemens, Airbus U.S. Space & Defense, Thales, John Deere, Roche, Munich Re, Deutsche Bahn, Thomson Reuters. Thomson Reuters and LSEG, the two information businesses most often compared to RELX, both appear. RELX does not, which proves nothing either way, because CloudSEK could only count what it could see.

The sentence in the report that should be printed and taped to the wall of every security operations center: "A package can disappear in minutes while copied credentials remain usable for weeks or months unless they are rotated." The poisoned package was on PyPI for 40 minutes in March. The FBI notice arrived in July. The arrests came in August. Elsevier's routing changed in September. Every one of those intervals is inside the window CloudSEK describes.

One name on CloudSEK's list deserves a second look. Vodafone Group appears with 83 exposed secrets. Vodafone Germany appears, per Help Net Security's reporting, on the 2026 LAPSUS$-branded victim list. That is a coincidence until someone with access to both incidents says otherwise, and we are not going to say otherwise. But it is the kind of coincidence a diligence team writes down.

The Australian Federal Police, in the charging announcement two weeks later, put the whole campaign at approximately 1,000 organizations, more than 500,000 compromised credentials, and at least 300 gigabytes of exfiltrated data. Half a million credentials, harvested by a crew whose leader was intermittently homeless, sitting in an archive that two arrests did not delete.

TeamPCP is not a gang. It is a market.

The word "group" undersells what TeamPCP is, and understanding that is the key to reading the Elsevier incident correctly.

Austin Larsen, principal threat analyst at Google Threat Intelligence Group, described it to Krebs: "It is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity." The community has a clubhouse. George Prepakis, who operates as @kernelstub, earlier this year tweeted a public invite link to a Matrix chat server he created and named Cybercats. That server is where TeamPCP and adjacent crews coordinate. Its administrators are the people to watch, and we will come back to one of them.

The structure explains the contest. TeamPCP ran a competition in which, as Krebs reports, "participants were scored based on the number of weekly and monthly downloads of packages they compromised, directly incentivizing them to target the most popular code libraries." The prize was $1,000 in Monero, which Dataminr called "a recruitment floor" and which the actor himself dismissed as "just like participation trophy." Krebs's reading of the contest's true function: "talent identification and malicious access acquisition at scale." A gang steals. A market recruits people to steal, scores them on reach, and keeps the inventory.

Then there is the center of gravity itself. In early July, Krebs interviewed TeamPCP's leader over Signal, having already worked out who he was. Ruben Ian Thomson, 21, of Cottesloe, who goes by Ellis, said he had earned about $20,000 in total from TeamPCP, that he was no longer choosing "between rent and food," and that before falling back in with the crew he had been homeless and moving between "some very unstable places." His operational security was, by Krebs's account, close to nonexistent: a single Gmail address and its variants threaded through BreachForums, Darkforums and HackerOne; companies incorporated under his real name since 2024, one of them called OPSEC Express; and a HackerOne registration under the name Ruben Thomson with the username Deadcatx3, an alias multiple security firms had already tied to TeamPCP.

Charlie Eriksen of Aikido Security gave Krebs the sentence that reframes the threat model: "They can be noisy, they can make mistakes. They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable." And they can still put a credential harvester in front of 434,000 pipelines.

Thomson and Michael Gaebler, 23, of Mandurah, were arrested on August 26 and charged with 14 offenses between them, including four counts each of unauthorized modification of data with intent to commit a serious offense. Thomson additionally faces a charge of dealing with proceeds of crime worth $100,000 or more, and a charge of failing to comply with an order to assist police in accessing a device, which carries up to ten years. Thomson was denied bail. The next court date was September 18.

That is the threat model now. Not a disciplined crew with custom tooling and a target list. A loose market in stolen cloud credentials, harvested at scale by people who are not especially careful, catalogued by download count, and consumed downstream by whoever wants to run an extortion brand this quarter. The credentials do not go away when two of the harvesters are arrested. They sit in someone's archive until they are used or rotated, and rotation is the victim's job.

The other RELX company

Here is the part that has not been written anywhere.

Elsevier is one of four RELX divisions. Another is LexisNexis. On February 24, 2026, a group calling itself FulcrumSec gained access to LexisNexis cloud infrastructure by exploiting React2Shell, CVE-2025-55182, in an unpatched React frontend that LawSites reported "had been left unaddressed for months." The container was running under an AWS role named LawfirmsStoreECSTaskRole with, per Dataminr's March 9 brief, "over-privileged access to production environments." From there the actor reached AWS Secrets Manager.

FulcrumSec's claims, as catalogued by Dataminr: 53 AWS Secrets Manager credentials, 98 supply chain credentials, 45 employee password hashes, plaintext customer passwords from support tickets, 536 Redshift tables, roughly 3.9 million database records, around 400,000 user profiles, and 118 users with .gov addresses that LawSites identified as including federal judges, law clerks, DOJ attorneys and SEC staff. FulcrumSec's manifesto mocked the victim: "the company that indexes the world's legal information could not index its own IAM policies."

LexisNexis said the accessed data was "mostly legacy, deprecated data from prior to 2020" and that the incident was contained.

Ninety-eight supply chain credentials. That phrase, in a February breach of a RELX division, is worth pausing on in light of everything above. Secrets Manager is where a company keeps the keys to other companies' services: the CDN, the registrar, the DNS provider, the payment processor, the identity provider. Nobody has said which 98 services those credentials unlocked, or whether any were shared across RELX divisions, or whether they were rotated. LexisNexis said "contained." Contained is not rotated.

Two connections need to be stated with exactly the weight they carry.

First, the CVE. React2Shell appears on the FBI's TeamPCP list. It is also the vulnerability FulcrumSec used against LexisNexis. But React2Shell was mass-exploited from December 2025 onward; Google, Microsoft and AWS each published on multiple actors using it, including China-nexus groups. A shared CVE proves nothing about shared operators.

Second, the people. This one is documented. In his August reporting on the arrests, Krebs published a screenshot of the Cybercats server and identified its administrators. His sentence, in full: "The Cybercats administrator 'SeesawSec' in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec, which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components." An administrator of TeamPCP's own coordination server is the person behind the crew that breached Elsevier's sister company.

So within one calendar year, actors in the same loosely organized network reached two of RELX's four divisions. One through an unpatched container with a path to the secrets vault. One through the routing layer that decides where the company's name resolves. And the network's own coordination server is run, in part, by the operator of the first breach.

The hypothesis, stated as one

No public evidence ties the Elsevier routing change to any specific stolen credential, to the LexisNexis breach, to FulcrumSec, or to any individual in TeamPCP's orbit. Elsevier has not said what happened and may never.

What the public record supports is narrower. A federal advisory says a network of actors harvested cloud access tokens and API keys at scale and told everyone to rotate them. CloudSEK counted the harvest at 2,500 organizations and 434,000 pipelines from a single package that was live for 40 minutes. An administrator of that network's coordination server runs the crew that took 98 supply chain credentials from a RELX division in February. A LAPSUS$-branded page, staged 19 days in advance, publicly credits that network with providing cover. Seven months after the LexisNexis breach and eleven weeks after the FBI notice, a second RELX division had its edge routing changed by someone with valid access, in a manner consistent with a compromised DNS or CDN control plane and inconsistent with an application exploit, and the traffic was sent to that page.

There are other roads to the same door, and honesty requires listing them. Someone could have phoned an Elsevier administrator claiming to be IT and talked them through approving a change, which is how the ShinyHunters-linked Salesforce campaign worked. Someone could have compromised a reseller or registrar account upstream of Elsevier, which is how the Syrian Electronic Army took nytimes.com in 2013. Someone could have bought an insider, which the original LAPSUS$ advertised for at $20,000 a week. Each of those is a valid credential story, not an exploit story. None of them requires the TeamPCP harvest. All of them end with a login that Elsevier's routing layer trusted.

Those facts are consistent with stolen edge credentials being used months after they were taken. They do not establish it. Only Elsevier's logs can, and Elsevier is not talking.

78 Minutes
The minimum verified window during which www.elsevier.com, submit.elsevier.com and evolve.elsevier.com returned HTTP 302 redirects to a LAPSUS$ extortion page on September 21, 2026. Cloudskope confirmed the redirect at 8:17, 8:29, 8:33 and 9:07 PM Central and found it cleared at 10:09 PM. Elsevier has not said when it began, when it ended, or why.
19 Days
The gap between September 2, when the Chapter II page was anchored in Arweave block 1,992,730, and September 21, when Elsevier's domains were pointed at it. Securonix documented the staging a week before the redirect. The destination was finished and waiting. Whoever changed Elsevier's routing did not build a page. They changed a setting.
2 of 4
RELX divisions compromised in 2026. LexisNexis (Risk and Legal) in February, through an unpatched React container with access to AWS Secrets Manager. Elsevier (Scientific, Technical and Medical) in September, through its edge routing. RELX's half-year results, published July 23 between the two incidents, mention neither.

Elsevier has been here before

Elsevier's silence this week is easier to read once you know that the company has a fourteen-year record of credential incidents, and a consistent way of describing them.

In late October 2012, an editor of Optics & Laser Technology noticed that reviewers had been invited to two of his manuscripts, and that he had not invited them. Someone had obtained his username and password for the Elsevier Editorial System, created reviewer accounts in the names of real scientists, and used them to file glowing reviews of papers that were then accepted. Eleven papers were retracted. Elsevier's spokesman, Tom Reller, told Retraction Watch: "Our team immediately launched an investigation and discovered that someone had been able to retrieve the EES username and password information for this editor." How it was retrieved was not disclosed. "Measures have been taken to prevent this from happening again." Which measures was not disclosed either.

In March 2019, Mossab Hussein of SpiderSilk found an Elsevier server running an unsecured Kibana dashboard that displayed user email addresses and passwords in plaintext, along with password-reset links, as they flowed through the system. Motherboard's Joseph Cox verified it by requesting a reset for a test account and watching the credential appear on the exposed server within minutes. Most of the accounts were .edu. Elsevier's statement: "it appears that a server was misconfigured due to human error. We have no indication that any data on the server has been misused." How long it had been open, and how many accounts passed through, were never stated.

In January 2022, a neuroscience PhD candidate named Jonny Saunders discovered that Elsevier embeds a unique hash in the metadata of every PDF a user downloads, a different one each time. Asked why, an Elsevier spokesperson told Motherboard: "The identifier in the PDF helps to prevent cybersecurity risks to our systems and to those of our customers," and "Fingerprinting in PDFs allows us to identify potential sources of threats so we can inform our customers for them to act upon." Asked which risks, the spokesperson sent links to news articles about ransomware. Saunders's reply is the sharpest thing anyone has written about Elsevier's security posture: "Justifying them as a tool to protect against ransomware is a straightforward admission that these codes are intended to identify the downloader: how would they help if not by identifying the compromised account or system?"

Put the three together. A company that has watched a single stolen editor credential corrupt peer review. A company that has leaked its own users' passwords in plaintext and called it human error. A company that fingerprints every document it serves so it can trace a compromised account back to its owner and warn the customer. That company has spent more than 20 hours knowing whether its own login portals were redirected while users typed passwords into them, and it has not warned anyone.

What a stolen credential is worth at a publisher

It is easy to file a 78-minute redirect under embarrassment. Consider what was behind the doors that were pointed elsewhere.

By RELX's own published figures, Elsevier runs more than 2,900 journals, receives almost three million manuscript submissions a year, publishes more than 630,000 articles, and coordinates 33,000 editors and more than 1.5 million reviewers. Its 2025 results say article submissions are "growing very strongly." The manuscript portal at submit.elsevier.com is where those three million submissions enter. Every one is unpublished research: a pharmaceutical trial result before the market knows it, a materials-science finding before the patent is filed, a priority claim in a field where being second is the same as being nowhere. The most valuable thing in academic publishing is not the article. It is the manuscript before it becomes one, and the submission portal is the only place all of them pass through.

Evolve is the other door. Sherpath, HESI, EAQ and the rest are how American nursing schools deliver coursework, run exams and remediate students who fail them. At many programs the HESI exit exam is a graduation requirement before a student can sit for licensure. Every student and instructor account on Evolve is a credential to a system that holds exam content, exam results and the personal information of the people who will staff the country's hospitals in two years.

The 2012 incident shows what one stolen editor credential does at Elsevier: eleven fraudulent papers in the scientific record. Securonix confirmed the Chapter II page had no credential form, so nobody who landed on it on September 21 was harvested by the page. But for 78 minutes the only thing standing between three million submitting authors, half a million nursing enrollments and a credential-harvesting page was the attacker's decision not to build one. Whoever could change where evolve.elsevier.com goes could have pointed it at a pixel-perfect copy of the Evolve login. They pointed it at a billboard instead. That is the attacker's restraint, not Elsevier's control, and a company cannot put an attacker's restraint in a security questionnaire.

Who LAPSUS$ is now, and who it is not

The original LAPSUS$ was reviewed by the Cyber Safety Review Board in 2023. The Board's findings are worth restating because they describe a playbook that has not changed. The group was "loosely organized," "some of the perpetrators were teenagers," and it breached well-resourced companies through "creative application of many techniques" rather than sophisticated tools: SIM swapping to intercept one-time codes, MFA fatigue that meant "spamming employees with MFA prompts with the goal of overwhelming them until they said yes," impersonating help desks over chat, buying valid credentials on underground markets, and advertising "as much as USD 20,000 per week" for insider access. Members were arrested in the UK and Brazil in 2022.

In August 2025 a collective calling itself Scattered LAPSUS$ Hunters appeared, claiming members of Scattered Spider, LAPSUS$ and ShinyHunters, with ShinyHunters as the organizing party. Google tracks its campaigns as UNC6040 and UNC6395. It claimed more than a billion records from Salesforce customers and operated through BreachForums until U.S. and French police seized the forum in October 2025.

The Salesforce campaign is the clearest published account of how this network gets in, and it is worth reading closely because it is the same shape as what happened to Elsevier. Google Threat Intelligence Group's June 2025 analysis describes operators who "impersonate IT support personnel in convincing telephone-based social engineering engagements," talk an employee through Salesforce's connected-app setup page, and get them to approve a modified copy of Salesforce's own Data Loader tool, sometimes branded "My Ticket Portal" to match the help-desk pretext. That single OAuth approval "inadvertently grants UNC6040 significant capabilities to access, query, and exfiltrate sensitive information." The extortion, tracked as UNC6240, arrives by email from addresses like shinycorp@tuta[.]com, sometimes "several months after the initial UNC6040 intrusion activity." Google's summary line: "In all observed cases, attackers relied on manipulating end users, not exploiting any vulnerability inherent to Salesforce."

No exploit. A phone call, a legitimate-looking tool, an authorization that the platform treated as the customer's own decision, and a delay of months between access and extortion. Change the platform from Salesforce to a CDN control panel and the sentence still reads correctly.

Through 2026, a LAPSUS$-branded leak site listed Virta Health in March, AYA Bank in Myanmar in June, and, per Help Net Security, Vodafone Germany. The Virta claim was real: Virta confirmed access between March 19 and 22, reported 14,636 affected individuals to HHS, and the leak site listed Virta on March 23, a day before Virta noticed.

Which brings the attribution question to where Securonix left it. The signature is valid at high confidence. Continuity with the 2021-2022 crew is low confidence: "the evidence supports continuity of narrative and persona more than continuity of personnel." Securonix offers three plausible operators: an existing 2026 LAPSUS$ partner responding to TeamPCP's disruption, an affiliate adopting the brand, or opportunistic impersonation. Dataminr adds the caution that LAPSUS$ branding is now used across multiple distinct clusters.

For the purposes of Elsevier's customers, it does not matter which. What matters is that the brand on the page, whoever holds it, sits inside the same network that the FBI described in July, that breached LexisNexis in February, and whose documented method for two years has been a valid login obtained from a human, not a hole in software.

This attack is thirteen years old and the fix is seven

Nothing about the technique is new, and that is the indictment.

On August 27, 2013, the Syrian Electronic Army took control of nytimes.com, twitter.co.uk and huffingtonpost.co.uk by logging into a reseller account at the registrar Melbourne IT and changing the DNS records. Melbourne IT's explanation, as reported by The Register, could be reprinted this week without editing: "They came in through the front door. If you've got a valid user name and password ... the assumption from our systems is that you are the authorised owner and user of that domain name." Its advice was equally durable: "For mission critical names we recommend that domain name owners take advantage of additional registry lock features available from domain name registries including .com." Some of the domains targeted through the same reseller account had the lock active, Melbourne IT said, "and were thus not affected." Registry lock existed in 2013. It stopped the attack on the domains that had it.

Between January 2017 and the first quarter of 2019, a state-backed campaign that Cisco Talos named Sea Turtle compromised "at least 40 different organizations across 13 different countries" by taking registrar credentials, registry access and the EPP keys that registrars use to talk to registries, then obtaining fresh TLS certificates from Let's Encrypt, Comodo and Sectigo for domains they did not own so that the man-in-the-middle looked legitimate to browsers. Talos's first recommendation: "a registry lock service, which will require an out-of-band message before any changes can occur." Its framing: "DNS is a foundational technology supporting the Internet. Manipulating that system has the potential to undermine the trust users have on the internet."

DNS hijacking of that kind is the reason the Department of Homeland Security issued its first-ever emergency directive. Emergency Directive 19-01, January 22, 2019, describes the attack in three sentences that map exactly onto what Elsevier's visitors experienced. "The attacker begins by compromising user credentials, or obtaining them through alternate means, of an account that can make changes to DNS records." Then "the attacker alters DNS records, like Address (A), Mail Exchanger (MX), or Name Server (NS) records, replacing the legitimate address of a service with an address the attacker controls." And "Because the attacker can set DNS record values, they can also obtain valid encryption certificates for an organization's domain names."

The directive gave every federal agency ten business days to do four things: audit all public DNS records to confirm they resolve where intended; change the passwords on every account that can modify DNS; add multi-factor authentication to every such account; and start monitoring certificate transparency logs for certificates the agency did not request. Four actions. Ten days. Written for agencies with a fraction of Elsevier's budget, published free, seven years ago.

Then the CSRB in 2023, reviewing LAPSUS$ specifically, recommended phishing-resistant MFA for exactly this class of actor. Then the FBI in July 2026 said to rotate cloud tokens. The fix has been published, in escalating levels of official urgency, four times in the period during which Elsevier's editorial system was hijacked, its password server was left open, and its domains were redirected. Whether Elsevier has registry lock on elsevier.com, phishing-resistant MFA on its CDN and registrar accounts, alerting on edge changes, and CT log monitoring are four yes-or-no questions. Any one of them answered "yes" would be worth saying out loud this week. Elsevier has said none of them.

The same move, four months earlier

We have been here before, and Instructure got the same treatment from this firm.

On May 7, 2026, at 3:30 PM Eastern, Canvas pages at Harvard, Penn, Duke, Wisconsin, Oklahoma and dozens of other universities began redirecting to a black screen with a red border titled "SHINYHUNTERS, rooting your systems since '19 ;)". It was finals week. Instructure's CISO, Steve Proud, had declared the breach contained on May 2. At 4:20 PM Instructure replaced the ransom page with a Canvas-branded notice reading "scheduled maintenance." The status page did not acknowledge an incident until 4:41 PM, on a surface students do not check mid-exam. Instructure paid the extortionists on May 11 and received, in its words, digital confirmation of data destruction.

KrebsOnSecurity cited our analysis of that incident. The passage he quoted:

Penn was the named victim. Instructure was the mechanism. The incident was treated as a Penn-specific story by most of the national press and quietly handled by Instructure as a customer-specific matter.

The same sentence structure holds now. Elsevier was the name on the page. RELX was the pattern.

Line the education-sector incidents up and read the disclosure column.

PowerSchool, December 2024. A support portal login with no MFA, a built-in export tool, roughly 6,500 districts. The company paid for deletion and accepted a video as proof. Districts were re-extorted in May 2025. Attribution pointed to ShinyHunters.

Canvas, May 2026. Free-for-Teacher accounts, 8,809 institutions, 275 million records, Instructure's Salesforce instance in the same campaign. Declared contained May 2, recompromised May 7, called scheduled maintenance, paid May 11. Two congressional committees, the Department of Education and a class action followed. ShinyHunters.

Elsevier, September 2026. Edge routing changed on three domains for at least 78 minutes. Reversed silently. No statement of any kind. A LAPSUS$-branded page inside the ShinyHunters-adjacent network.

Not one of the three required a software vulnerability at the victim. Every one was a login. And each vendor said less than the one before. PowerSchool at least notified. Instructure lied and then walked it back. Elsevier has not opened its mouth.

What RELX has told its shareholders

RELX PLC trades on the London, Amsterdam and New York exchanges and files an annual report on Form 20-F with the SEC. Its 2025 results, presented February 12, 2026 by CEO Erik Engstrom and CFO Nick Luff, report £9,590 million in revenue: £3,485 million from Risk, £2,714 million from Scientific, Technical and Medical, which is Elsevier, £1,806 million from Legal, which is LexisNexis, and £1,186 million from Exhibitions. Elsevier's adjusted operating margin was 38.1 percent, up from 37.4. The only reference to cybersecurity in the presentation is a clause in the forward-looking-statements disclaimer.

Twelve days after that presentation, FulcrumSec was inside LexisNexis's AWS environment.

RELX published its half-year results on July 23, 2026, five months after the LexisNexis breach and three weeks after the FBI FLASH. Revenue of £4,871 million, adjusted operating profit of £1,727 million. The document's treatment of cyber risk is confined to the principal-risks boilerplate: "These databases and information are a target for compromise and face a risk of unauthorised access," and the standard forward-looking disclaimer about "compromises of our cybersecurity systems or other unauthorised access to our databases." The LexisNexis incident is not mentioned. The name LexisNexis appears only inside product names.

Whether a breach involving 400,000 user profiles, 118 government accounts and 53 secrets-vault credentials is material to a company with £9.6 billion in revenue is a judgment for RELX's board and its auditors. Whether a 78-minute hijack of a division's homepage is material is likewise theirs to make. But the pattern is not a judgment. It is a fact. Two divisions, two incidents, seven months apart, actors in the same network, and not one sentence in any RELX filing, results release, or press statement that acknowledges either.

Elsevier's CEO is Kumsal Bayazit. Its Chief Technology Officer is Jill Luber. Its Global General Counsel is Jan bij de Weg. Between them they have had more than 20 hours to say what happened to the login portal that half a million nursing course enrollments depend on. They have used that time to announce a study about sleep.

What Elsevier should have done by now

Set aside whether the redirect could have been prevented. What is not a hard problem is what a company should say after it. There is a playbook. Elsevier has not opened it.

  1. Acknowledge the incident on the surface where users experienced it. A notice on evolve.elsevier.com and submit.elsevier.com stating that between roughly 7:45 and 10:10 PM Central on September 21 the sites redirected to a third-party page. One paragraph. It has not appeared.
  2. Tell users what to do about credentials. Anyone who attempted to sign in during the window should reset their password and any reused password. That sentence costs nothing and Elsevier has not written it. Help Net Security has asked the question directly.
  3. State the mechanism. DNS record, CDN rule, registrar account, or something else. Elsevier knows. Its customers are guessing. So is everyone writing about it.
  4. State what was and was not reached. Was the change confined to routing, or was the account that made it capable of more? That is the difference between an embarrassing evening and a breach, and Elsevier is the only party that can answer it.
  5. Confirm the FBI notice was actioned, and the 2019 directive too. FLASH-20260702-01 told organizations to rotate cloud credentials and API keys in July. ED 19-01 told agencies in 2019 to audit DNS records, change DNS-capable passwords, add MFA and watch CT logs. A one-line confirmation that Elsevier's edge and registrar credentials were rotated after July 2 and sit behind phishing-resistant MFA, or an admission that they did not, would settle the most important open question in this piece.
  6. Put it in the record. RELX's next results release is the natural place. So is a Form 6-K, if the board judges it material. Silence in both is a choice, and it is the same choice Instructure made in May with results that arrived from four directions at once.

Six things. None expensive. None requiring new technology. All undone.

What boards should be asking this week

For institutions that run on Elsevier, four questions for Monday.

First, what did Elsevier tell us, if anything, and when? If the answer is nothing, that is itself the finding, and it belongs in the vendor file before the next renewal.

Second, which of our students, faculty and researchers attempted to sign in to an Elsevier property between 7:45 and 10:10 PM Central on September 21, and have we told them to reset? Elsevier will not. Somebody has to.

Third, what unpublished work did our researchers have in submit.elsevier.com that night, and what is our exposure if the account that changed the routing could also read the portal? Nobody can answer that yet. The question should be on file so that when Elsevier finally speaks, someone is holding it.

Fourth, what is our position on a vendor that has now been compromised at two divisions in a year and disclosed neither? That is a procurement question and a risk-committee question, and it should be asked out loud.

For everyone else, one question. When the FBI said in July to rotate cloud tokens and API keys, did the ticket go to engineering and close when CI/CD secrets were rotated? Because the Cloudflare API token, the Route 53 credentials and the registrar login one person has held since 2019 are cloud tokens too. They sit in the same vaults and the same pipelines CanisterWorm was harvesting. They control what the internet sees when someone types your company's name. And they almost never make the list.

For sponsors and acquirers

Edge infrastructure belongs in diligence and it is usually absent. A target can hold clean SOC 2 attestations, a tidy vulnerability program and a fully patched estate while one unrotated token lets an outsider place their own page on the primary domain within minutes, as it did here, and as it did at Canvas.

The questions cost nothing. Who holds registrar access, and is registry lock on. Whether DNS and CDN accounts sit behind phishing-resistant MFA, which the CSRB recommended in 2023 for exactly this class of actor. Whether edge changes generate alerts to a human. Whether anyone is watching certificate transparency logs for certificates the company did not request. Whether anyone can produce the audit log on request. And, since July, whether the FBI notice was actioned beyond the engineering org.

A week to answer. More predictive than any attestation.

What we are not saying

We are not saying LAPSUS$, TeamPCP, FulcrumSec or any named individual changed Elsevier's routing. We are not saying the LexisNexis credentials were used against Elsevier. We are not saying the Vodafone name appearing on both CloudSEK's list and the LAPSUS$ victim list is anything but a coincidence until someone shows otherwise. We are not saying the Chapter II operators are the 2022 crew; Securonix says they probably are not. We are not saying Elsevier's user data was taken; nothing has been claimed and the destination page collected nothing.

We are saying that the public record, read in full and in order, describes a network, a credential harvest, a federal warning, two RELX divisions, a fourteen-year history of the same failure at the same company, a fix that has been public since 2013, and a company that has decided its customers do not need to know. If Elsevier or RELX would like to correct any of that, this page will be updated the same hour.

Our record of these incidents

Sources

Conclusion

A page staged on September 2. A federal warning on July 2. A sister company breached on February 24. A homepage redirected on September 21. And a parent company that has told its shareholders, its customers and the nursing students who typed their passwords that night exactly nothing. Elsevier was the name on the page. RELX was the pattern.

CLOUDSKOPE VIEW

Cloudskope advises boards, deal teams and general counsel on the questions this incident raises: who holds edge and registrar access, whether it was in scope of the July FBI notice, and what the disclosure position is before a redirect appears on your own homepage.

TAGS