← Back to Daily Briefing (#LAPSUS$)

Elsevier Web Properties Hijacked to Display LAPSUS$ Extortion Page

Published September 25, 2026

On September 21, 2026, attackers successfully executed a DNS hijacking attack against Elsevier, compromising the domain registrar records for elsevier.com, scopus.com, and sciencedirect.com. For 78 minutes, legitimate traffic was redirected via HTTP 302 responses to a malicious host (185.XX.XX.XX/24) controlled by the LAPSUS$ threat group. The redirection served a "Chapter II" extortion page featuring a JavaScript countdown and taunts directed at federal law enforcement. While no data exfiltration or malware delivery was confirmed, the incident demonstrates a critical supply chain vulnerability within the domain management lifecycle, impacting tens of thousands of global academic users.

  • Incident Overview & Timeline
  • Simultaneous compromise of three major Elsevier web portals.
  • Redirection window: 19:49 CT to 22:09 CT (78-minute duration).
  • Users encountered a LAPSUS$ "Chapter II" extortion landing page.
  • Service interruption affected a massive global academic user base.

  • Attack Mechanics & Technical Vector

  • Unauthorized modification of DNS A/AAAA (or CNAME) records at the registrar level.
  • Legitimate hostnames were resolved to the attacker-controlled IP range 185.XX.XX.XX/24.
  • The malicious host utilized a low-trust Certificate Authority (SSL serial: 0xAB12) to serve the page.
  • Attackers utilized HTTP 302 redirects to bypass standard site availability.

  • Threat Actor Profile: LAPSUS$

  • Claimed responsibility via a signed statement on the hijacked Elsevier landing page.
  • Known for high-profile, rapid-turnaround intrusions targeting large enterprises (e.g., NVIDIA, Okta).
  • Tactics focus on extortion and reputational damage through DNS and credential-based hijacking.
  • Group operates with fluid membership and high-impact, low-persistence execution.

  • Indicators of Compromise & Defensive Actions

  • Malicious Infrastructure: IP range 185.XX.XX.XX/24 hosting extortion content.
  • DNS Event Window: 20260921T19:49:00Z to 20260921T22:09:00Z.
  • Mitigation: Implement DNSSEC, registrar-level account MFA, and strict registrar locks.
  • Monitoring: Enable real-time alerting for all DNS record changes via registrar APIs.

  • Impact & Strategic Lessons

  • Significant reputational risk and potential breach of service-level agreements (SLAs).
  • Exposed critical supply chain weakness in third-party registrar security controls.
  • Underscores the necessity of robust change management and rapid DNS rollback protocols.
  • Highlights the danger of unauthorized administrative access to domain management interfaces.

Related posts

  1. techjacksolutions.com — Elsevier Web Properties Temporarily Hijacked to Display LAPSUS$ Extortion Page
  2. www.helpnetsecurity.com — Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
  3. news4hackers.com — Elsevier Domains Hijacked: Redirected to LAPSUS$ ‘Chapter II’ Page
  4. Cloudskope
  5. Cybersecurityventures
  6. Dysruptionhub
  7. Mallory
  8. News

LINK COPIED TO CLIPBOARD