Elsevier.com, Evolve.elsevier.com, and Submit.elsevier.com briefly redirected visitors to a page branded “LAPSUS$ GROUP, Chapter II.” Cloudskope said the apparent hijack lasted at least 78 minutes and likely resulted from a DNS or CDN edge-configuration change. Related reports said Evolve, Sherpath, and ClinicalPharmacology users encountered extortion-themed pages linked to lapsus[.]ar[.]io and lapsus[.]bz, disrupting access to examinations and simulation-charting resources used by medical and nursing students.
The affected sites were cleaned and restored, but Elsevier had not publicly explained the cause or disclosed whether credentials, customer data, or internal systems were compromised. The page claimed a connection to LAPSUS$ and hinted at another victim, but researchers cautioned that available evidence does not establish attribution or continuity with the original 2021–2022 LAPSUS$ operation; claims involving GSDD APIs also remain unsubstantiated.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Elsevier.com, Evolve.elsevier.com, and Submit.elsevier.com redirected visitors to a page branded “LAPSUS$ GROUP, Chapter II.” Cloudskope observed the redirect from approximately 7:49 p.m. CT until before 10:09 p.m. CT, for at least 78 minutes.
Sorami Consulting reported redirects affecting Elsevier Evolve, Sherpath, and ClinicalPharmacology to extortion-themed pages associated with LAPSUS$, referencing lapsus[.]ar[.]io and lapsus[.]bz. Public discussion described nursing and medical students being unable to access exams and simulation charting; the report did not establish the compromise mechanism or independently verify attribution.
Elsevier cleaned and restored the affected domains to functioning status following the temporary redirection. The company had not publicly explained the cause or said whether credentials or other user data were compromised.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.