Academic publisher Elsevier hit by LAPSUS$ redirect attack

Summary

Academic publisher Elsevier was the target of a redirect attack orchestrated by the LAPSUS$ cybercrime group. Instead of accessing academic journals, customers were presented with the group's branding. This incident highlights the potential for disruptions caused by sophisticated threat actors targeting major institutions.

IFF Assessment

FOE

The article describes an attack by a known cybercrime group that disrupted access to a major publisher's services, representing a negative event for defenders.

Defender Context

This incident involving Elsevier and LAPSUS$ serves as a reminder that even large, established organizations are targets for disruptive attacks. Defenders should be aware of the tactics used by groups like LAPSUS$ and ensure robust defenses against redirection and credential compromise are in place.

Read Full Story →