Three Elsevier web properties pushed visitors and authentication traffic to an extortion page branded “LAPSUS$ GROUP, Chapter II” for at least 78 minutes on the evening of September 21.
Cloudskope researchers tracked the redirect from about 7:49pm CT until it cleared before 10:09pm CT. The affected properties were Elsevier.com, Evolve.elsevier.com, and Submit.elsevier.com. Evolve is the learning management system that nursing and allied health programs use for coursework and exams, which is why students reported being locked out mid-session.
The redirect reached clinical drug endpoints
The damage was not confined to classrooms. Sorami Consulting reported that production authentication endpoints for Elsevier’s ClinicalPharmacology and Gold Standard Drug Database services – including the api.gsdd.net token endpoint – returned attacker-controlled pages instead of valid access tokens. Gold Standard drug and pharmacogenomic content feeds clinical decision support and prescribing workflows inside hospitals and pharmacies, so token failures there touch medication reference at the point of care.
The splash page carried a PGP-signed statement taunting the FBI and counting down to a future victim. LAPSUS$ declared a “permanent” retirement in July; Securonix analysts say no evidence reviewed so far establishes continuity with the original 2021-2022 crew.
Elsevier told DataBreaches that its team resolved the issue immediately and found no sign that core platforms, customer data, research content, or operational systems were compromised. It has not said whether credentials were exposed. Researchers suspect a DNS record, a CDN redirect rule, or the account controlling them.