Is Sherpath Hacked? What Happened to Evolve and Elsevier on September 21

Evolve, the sign-in door for Sherpath, HESI and EAQ, redirected to an extortion page for roughly two hours on September 21. Here is what happened and what to do.
The short answer
No. On the evidence available tonight, Sherpath itself was not hacked, and neither were your coursework, your grades, or your HESI results.
What happened is narrower. On the evening of Sunday, September 21, 2026, three Elsevier web addresses stopped sending visitors to Elsevier and started sending them to a page run by an extortion group calling itself LAPSUS$. One of those addresses was evolve.elsevier.com, which is how students reach Sherpath, HESI, EAQ, and SimChart.
The redirect was cleared. As of 10:09pm Central, every Elsevier address loads normally again.
If you searched for "Sharepath," the platform is spelled Sherpath. It is Elsevier's nursing and health-professions coursework platform, and you sign in to it through Evolve.
What was actually affected
- evolve.elsevier.com redirected. This is the sign-in door for Sherpath, HESI, EAQ, SimChart, and Shadow Health.
- www.elsevier.com redirected, starting later in the evening.
- submit.elsevier.com redirected. This is where researchers upload manuscripts.
- ScienceDirect was never affected and loaded normally throughout.
Timeline, Central Time, September 21
- 7:49pm. First public report of submit.elsevier.com redirecting.
- 7:57pm. A nursing student opening an Evolve link lands on the LAPSUS$ page.
- 8:17pm. Cloudskope confirms Evolve and the manuscript portal both redirecting.
- 8:29pm. The Elsevier homepage joins them.
- 9:07pm. Still redirecting.
- 10:09pm. Cleared. All addresses resolve normally.
Elsevier has issued no statement.
Nothing was encrypted and no student data has been claimed. For roughly two hours, the addresses themselves pointed somewhere else.
What you should do
The question that matters is not whether Sherpath was hacked. It is whether you typed your password into that page.
If you tried to sign in to Evolve between about 7:45pm and 10:09pm Central on September 21:
- Change your Evolve password now.
- Change it anywhere else you used the same password. This is the step people skip, and it is the one that matters most.
- Turn on multi-factor authentication if your school offers it.
- Watch for phishing over the next few weeks. Emails referencing your HESI results, your Evolve account, or a "security update" deserve suspicion.
If you only saw the strange page and closed it: you are almost certainly fine. Loading a page does not hand over your credentials. Change your password anyway if you are unsure whether you typed anything.
Do not click links in any email about this incident. Go to evolve.elsevier.com by typing it yourself. Events like this are followed by phishing that impersonates the recovery process.
Was my exam or coursework lost?
No evidence suggests otherwise. Nothing was encrypted, no ransom was demanded against Elsevier, and no student records have been claimed by anyone. This was a redirect, not an intrusion into coursework systems, as far as anyone outside Elsevier can currently verify.
If you were mid-exam when it happened, contact your program. Proctored HESI attempts interrupted by a platform outage are normally handled by the school, not by Elsevier support.
Why this happened, in plain terms
Every website address has a control layer that decides where traffic goes: DNS records, a content delivery network, and the registrar account that governs both. Change a setting there and the address stays the same while the destination changes. Visitors type the real address and land somewhere else.
That is what took place. MITRE ATT&CK classifies it as T1584.001, Compromise Infrastructure: Domains, which covers hijacking a victim's domains through registrar or DNS-provider account access.
It was not DNS cache poisoning. Poisoning corrupts a resolver's cache and fades on its own. This was consistent across networks until someone reversed it.
Three Elsevier properties failed together while ScienceDirect, hosted separately, did not. That points to one compromised control plane rather than three separate break-ins.
For universities and nursing programs
Two things are worth doing this week.
Tell affected students to reset Evolve passwords and any reused credentials. Most will not do it unless asked directly, and password reuse is what converts a two-hour redirect into a lasting problem.
Then ask the same question about your own environment. DNS, CDN, and registrar consoles are among the most privileged accounts any institution holds, and they usually sit outside identity governance, outside privileged access review, and sometimes outside multi-factor authentication. They are rarely inventoried because nobody thinks of them as systems. They are the systems that decide what the internet sees when someone types your name.
Full analysis
Our complete verified timeline, the technical breakdown, and what remains unknown are documented in the Breach Library: Elsevier.com, Evolve and Manuscript Submission Redirected to LAPSUS$.
We will update both pages when Elsevier says something.
Sherpath was not hacked. The address that takes you there pointed somewhere else for about two hours. If you typed your password during that window, change it now and change it anywhere you reused it.
Cloudskope publishes verified breach analysis for boards, deal teams, and general counsel. Our Cyber Risk Assessment covers DNS, CDN, and registrar access, the control plane behind this incident.
.png)
.png)
