Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-24 · updated: 2026-09-24 · tags: [incident, education, breach] · confidence: high · severity: high · affected_sectors: [education] · au_impact: false

Academic publisher Elsevier confirmed that visitors to select platforms were redirected to a LAPSUS$ leak page following an attack on 21 September, with a nursing student's Reddit post on 22 September showing the criminal crew's calling card in place of textbook access. The Amsterdam-based publisher says its security team resolved the issue and restored service, and characterises it as "a narrowly scoped, limited-duration event involving the temporary redirection of traffic for certain web properties", with no indication that core platforms, customer data, research content or operational systems were compromised. It would not say which platforms were affected or for how long the redirect was in place — the operationally important detail for any institution that needs to determine whether users were exposed to a credential-harvesting page. Elsevier is best known for ScienceDirect, which hosts scientific, technical and medical research and sits inside university library authentication flows; a redirect at that layer intersects with institutional single sign-on, which is why a "limited" event still warrants a user-credential review.

Attribute Detail
Sector Education
Date 2026-09-24
Source The Register
Reliability Tier 2
Breach classification Confirmed breach