Subscribe Sign in

Academic publisher Elsevier hit by LAPSUS$ redirect attack

1 min read Rewritten in plain language

Security

Show what we removed Rules applied: C1 C2 D3×6 D4 E3 all 30 rules
  • Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page.
  • Amsterdam-based Elsevier told The Register it was briefly compromised following an attack Monday, but played down the wider impact.
  • After a protracted break, the LAPSUS$ name returned in 2025, partnering with Scattered Spider and ShinyHunters in another string of cyberattacks affecting household names, before splitting up and activity dropping to a modest six attacks per month, according to SOCRadar.

3 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

LAPSUS$, meanwhile, is better known for its criminal enterprises, namely big-name cyberattacks on the likes of Rockstar Games and more recently, attacks on Adidas and GitHub.

Headline check

All two things this headline claims are in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. How this is checked

Customers got crime crew's calling card instead of access to journals.

Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page.

One Reddit user, a self-described nursing student, highlighted the issue on September 22, posting a screenshot of LAPSUS$’s leak site after trying to access “homework and textbooks.”

“Every time I try to open the Elsevier website, I am met with this,” they wrote.

Amsterdam-based Elsevier told The Register it was briefly compromised following an attack Monday, but played down the wider impact.

LAPSUS$, meanwhile, is better known for its criminal enterprises, namely big-name cyberattacks on the likes of Rockstar Games and more recently, attacks on Adidas and GitHub.

After a protracted break, the LAPSUS$ name returned in 2025, partnering with Scattered Spider and ShinyHunters in another string of cyberattacks affecting household names, before splitting up and activity dropping to a modest six attacks per month, according to SOCRadar.

Shortened to 1 minute of reading, this version reads 5.3 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 8.5 11 68 -0.5 39
Mundane Readneutralized from The Register 6.7 11 68 -0.5 39

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works