Elsevier Domain Hijack Redirects to LAPSUS$ Page

Elsevier Domains Hijacked to Redirect to LAPSUS$ Extortion Page

MEDIUM
September 22, 2026
4m read
CyberattackThreat Actor

Impact Scope

Affected Companies

Elsevier

Industries Affected

Media and EntertainmentEducationTechnology

Related Entities

Threat Actors

Organizations

CloudskopeCloudflareFBI

Other

Elsevier Virta Health

Full Report

Executive Summary

On September 21, 2026, several domains owned by the major academic publisher Elsevier were temporarily hijacked. For a period of over an hour, visitors to Elsevier.com and two other related domains were redirected to an extortion page bearing the name of the LAPSUS$ group. The incident appears to have been a DNS or CDN-level hijacking, designed for public disruption rather than data theft. While the page used the LAPSUS$ branding, security researchers caution that there is no confirmed link to the original members of the group, which was largely dismantled in 2022. Elsevier has since regained control of its domains and restored normal service.


Threat Overview

The incident was a high-profile act of disruption targeting a major global publisher. The attackers gained control over the traffic routing for three Elsevier domains: Elsevier.com, Evolve.elsevier.com, and submit.elsevier.com. They implemented an HTTP 302 redirect, sending all incoming traffic to an external page they controlled.

This page was branded "LAPSUS$ GROUP, Chapter II" and contained taunts aimed at the FBI, a hallmark of the original group's style. The use of the LAPSUS$ name is likely an attempt by a new or copycat actor to gain notoriety by leveraging a well-known brand in the cybercrime world. The attack vector was likely a compromised account for Elsevier's DNS provider or Content Delivery Network (CDN), such as Cloudflare, which would allow an attacker to modify traffic routing rules.


Technical Analysis

The attack was executed by modifying web traffic routing configurations. There are two primary ways this could have been achieved:

  1. DNS Hijacking: The attacker could have gained access to Elsevier's domain registrar or DNS hosting account. They could then have changed the A or CNAME records for the affected domains to point to a server they controlled, which would then issue the redirect. This is a form of T1483 - Domain Trust Discovery, but weaponized for redirection.
  2. CDN Hijacking: As speculated by researchers, the attacker may have compromised Elsevier's account with their CDN provider (reportedly Cloudflare). Within the CDN's control panel, an attacker could create a redirect rule (like a Page Rule in Cloudflare) that intercepts all traffic for a given domain and issues an HTTP 302 redirect to an external URL (T1574.012 - COR_PROFILER, conceptually similar in redirecting execution flow).

The use of an HTTP 302 (temporary) redirect suggests the attacker's goal was temporary disruption and public embarrassment, not a permanent takeover. The incident lasted for a confirmed 78 minutes before Elsevier's security team was able to revert the malicious changes.


Impact Assessment

The primary impact of this incident was reputational. The hijacking of a major corporation's primary domains is embarrassing and can erode customer trust. It also caused a temporary service disruption for users trying to access the affected sites, including researchers attempting to submit manuscripts. There is no evidence that any data was compromised or that Elsevier's internal systems were breached. The incident serves as a reminder that an organization's security perimeter extends to its third-party service providers, including domain registrars and CDNs, and that accounts for these services are high-value targets for attackers.


IOCs — Directly from Articles

No specific IPs or domains for the malicious redirect page were provided in the source articles.


Cyber Observables — Hunting Hints

To detect and prevent similar hijacking incidents, organizations can monitor the following:

Type
log_source
Value
DNS Monitoring Services
Description
External services that continuously check a domain's DNS records and alert on any changes to A, CNAME, or NS records.
Context
External Monitoring Tools
Confidence
high
Type
log_source
Value
CDN Audit Logs
Description
Monitor for any changes to redirect rules, page rules, or other traffic management configurations within the CDN provider's dashboard.
Context
Cloudflare Audit Logs, etc.
Confidence
high
Type
other
Value
Certificate Transparency Logs
Description
Monitor for newly issued SSL/TLS certificates for your domains or subdomains, which could indicate an attacker is preparing to impersonate your site.
Context
CT Log Monitoring Services
Confidence
medium
Type
other
Value
User login to DNS/CDN provider
Description
Alert on logins to registrar or CDN provider accounts from unusual IP addresses, geolocations, or at unusual times.
Context
Identity and Access Management (IAM) Logs
Confidence
high

Detection & Response

Detection:

  • Configuration Change Monitoring: Implement real-time alerting for any changes made in your DNS and CDN provider accounts. This is the most effective way to catch a malicious modification quickly. D3FEND's System Configuration Permissions (D3-SCP) is a related preventative control.
  • External Uptime/Integrity Monitoring: Use external services that periodically check your website's availability and content. An unexpected redirect or content change would trigger an alert.

Response:

  1. Revert Changes: Immediately access the compromised DNS/CDN account and revert the malicious changes.
  2. Revoke Sessions & Reset Credentials: Force a logout of all active sessions in the provider account and reset the password for the account.
  3. Enable MFA: If not already enabled, enforce mandatory multi-factor authentication for all users with access to the DNS/CDN provider accounts.
  4. Audit Logs: Review the provider's audit logs to determine the source IP of the attacker, the exact time of the change, and whether any other modifications were made.

Mitigation

  • Multi-Factor Authentication (MFA): Enforce mandatory, phishing-resistant MFA (e.g., FIDO2 security keys) on all accounts for critical third-party services like domain registrars and CDN providers. This is the single most effective defense against account takeover (M1032 - Multi-factor Authentication).
  • Least Privilege Access: Limit the number of users who have administrative access to these critical accounts. Use role-based access control (RBAC) to grant users only the permissions they need.
  • Registrar Lock: Enable the "Registrar Lock" or "Transfer Lock" feature at your domain registrar. This prevents unauthorized transfers of your domain to another registrar.
  • Regular Audits: Periodically audit the configurations and user accounts within your DNS and CDN providers to ensure they align with your security policies.

Timeline of Events

1
September 22, 2026
This article was published
2
September 21, 2026
The domain redirect is first verified as being live.
3
September 21, 2026
The malicious redirect is confirmed to have been removed and service restored.

MITRE ATT&CK Mitigations

Enforce phishing-resistant MFA on all administrative accounts for critical external services like DNS and CDN providers.

Apply the principle of least privilege to DNS/CDN accounts, limiting the number of users with administrative rights.

Audit

M1047enterprise

Implement real-time monitoring and alerting on configuration changes within DNS and CDN provider accounts.

Timeline of Events

1
September 21, 2026

The domain redirect is first verified as being live.

2
September 21, 2026

The malicious redirect is confirmed to have been removed and service restored.

Sources & References

Elsevier Domains Hijacked, Redirected to LAPSUS$ (2026)
Cloudskope (cloudskope.com) September 22, 2026
Brief hijack makes Elsevier domains redirect to LAPSUS$ "Chapter II" page
Help Net Security (helpnetsecurity.com) September 22, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

ElsevierLAPSUS$Domain HijackingDNS HijackingCDNCloudflareCyberattack

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.