Three web portals belonging to Dutch academic publisher Elsevier were briefly hijacked, redirecting visitors to a page styled as 'LAPSUS$ GROUP, Chapter II.' The page carried a signed statement that mocked the FBI and displayed a countdown to an unspecified future victim, according to a report from Help Net Security citing security firm Cloudskope.
The report does not specify how the redirect was achieved or how long it lasted. The LAPSUS$ branding suggests a possible connection to the hacking group, but the source does not confirm their involvement. Cloudskope's findings were shared via Help Net Security, and no further technical details have been published.
Domain-level redirects are a concern for publishers because users may not notice the change before entering credentials or downloading content. Even a brief hijack, as described here, can undermine trust in a well-known academic brand and expose visitors to phishing or malware.