VYPR
breachPublished Sep 22, 2026· 1 source

LAPSUS$ Group Re-emerges with Elsevier Domain Hijacking

The notorious LAPSUS$ hacking group appears to have resurfaced, hijacking Elsevier's domains for over an hour and redirecting users to a taunting message.

Elsevier's online presence was disrupted for approximately 78 minutes on September 21, 2026, as three of its key domains were hijacked, redirecting unsuspecting users to a page branded with the LAPSUS$ Group's insignia. The incident, which began around 7:49 PM CT and was resolved before 10:09 PM CT, affected the main company website (Elsevier.com), the Evolve learning portal, and the Submit manuscript submission portal.

The hijacked pages displayed a message from the "LAPSUS$ GROUP, Chapter II," which included taunts directed at the FBI and a countdown timer hinting at a future victim. This resurgence is significant as the LAPSUS$ group was believed to be largely inactive since late 2022, following arrests and convictions of some of its members. However, remnants of the group, or imitators, have continued to surface, with some members potentially joining the Scattered Lapsus$ Hunters collective.

Researchers from Cloudskope suggested that the attack vector likely involved a change at the DNS or CDN edge, such as a modified DNS record, a CDN redirect rule, or compromised account credentials managing these services. While a Chinese-language forum post claimed the attackers altered Elsevier's Cloudflare redirect rules, this could not be independently verified. Elsevier has not yet provided a detailed explanation of the incident or confirmed whether user data or credentials were compromised, though the affected domains are now functional.

The LAPSUS$ group gained notoriety for its high-profile extortion-focused attacks against major technology firms including Microsoft, Okta, Nvidia, and Uber. Despite the arrests, the group's branding has continued to appear in connection with data breaches and extortion attempts, notably through the Scattered Lapsus$ Hunters collective. In 2026 alone, Lapsus$-branded leak sites have targeted organizations like Virta Health, Vodafone Germany, and AYA Bank.

This latest incident, with its bold taunting message and countdown, suggests a renewed or continued operational capability under the LAPSUS$ banner. The message specifically hinted at targeting a "global company generating over $50 billion in annual revenue," indicating a potential focus on high-value targets. The exact nature of this threat and the group's current operational structure remain subjects of ongoing investigation.

Security firm Securonix noted that current analysis has not established a direct personnel continuity between the original 2021-2022 LAPSUS$ cluster and the actors behind this recent activity. This raises questions about whether this is a revival of the original group, a splinter faction, or a new entity adopting the LAPSUS$ name and tactics. Regardless, the incident serves as a stark reminder of the persistent threat posed by sophisticated threat actors, even those believed to be dormant.

The hijacking of Elsevier's domains highlights the critical importance of robust DNS and CDN security. The ability for an attacker to redirect traffic from major websites, even for a limited time, can have significant reputational and operational impacts. Organizations must maintain vigilant monitoring of their edge infrastructure and have rapid response protocols in place to detect and mitigate such disruptions.

Synthesized by Vypr AI
LAPSUS$ Group Re-emerges with Elsevier Domain Hijacking · VYPR