On September 21, 2026, several domains owned by the major academic publisher Elsevier were temporarily hijacked. For a period of over an hour, visitors to Elsevier.com and two other related domains were redirected to an extortion page bearing the name of the LAPSUS$ group. The incident appears to have been a DNS or CDN-level hijacking, designed for public disruption rather than data theft. While the page used the LAPSUS$ branding, security researchers caution that there is no confirmed link to the original members of the group, which was largely dismantled in 2022. Elsevier has since regained control of its domains and restored normal service.
The incident was a high-profile act of disruption targeting a major global publisher. The attackers gained control over the traffic routing for three Elsevier domains: Elsevier.com, Evolve.elsevier.com, and submit.elsevier.com. They implemented an HTTP 302 redirect, sending all incoming traffic to an external page they controlled.
This page was branded "LAPSUS$ GROUP, Chapter II" and contained taunts aimed at the FBI, a hallmark of the original group's style. The use of the LAPSUS$ name is likely an attempt by a new or copycat actor to gain notoriety by leveraging a well-known brand in the cybercrime world. The attack vector was likely a compromised account for Elsevier's DNS provider or Content Delivery Network (CDN), such as Cloudflare, which would allow an attacker to modify traffic routing rules.
The attack was executed by modifying web traffic routing configurations. There are two primary ways this could have been achieved:
T1483 - Domain Trust Discovery, but weaponized for redirection.T1574.012 - COR_PROFILER, conceptually similar in redirecting execution flow).The use of an HTTP 302 (temporary) redirect suggests the attacker's goal was temporary disruption and public embarrassment, not a permanent takeover. The incident lasted for a confirmed 78 minutes before Elsevier's security team was able to revert the malicious changes.
The primary impact of this incident was reputational. The hijacking of a major corporation's primary domains is embarrassing and can erode customer trust. It also caused a temporary service disruption for users trying to access the affected sites, including researchers attempting to submit manuscripts. There is no evidence that any data was compromised or that Elsevier's internal systems were breached. The incident serves as a reminder that an organization's security perimeter extends to its third-party service providers, including domain registrars and CDNs, and that accounts for these services are high-value targets for attackers.
No specific IPs or domains for the malicious redirect page were provided in the source articles.
To detect and prevent similar hijacking incidents, organizations can monitor the following:
Detection:
System Configuration Permissions (D3-SCP) is a related preventative control.Response:
M1032 - Multi-factor Authentication).Enforce phishing-resistant MFA on all administrative accounts for critical external services like DNS and CDN providers.
Apply the principle of least privilege to DNS/CDN accounts, limiting the number of users with administrative rights.
The domain redirect is first verified as being live.
The malicious redirect is confirmed to have been removed and service restored.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.