Academic publisher Elsevier hit by LAPSUS$ redirect attack
Academic publisher Elsevier has been targeted in a LAPSUS$ redirect attack, resulting in unauthorized access to internal systems and potential data compromise. The attack highlights the ongoing threat posed by sophisticated cybercriminal groups and the need for robust security measures within organizations handling sensitive information.
This article discusses a recent attack on Elsevier, a major academic publisher, attributed to the LAPSUS$ group. The attack involved a redirect scheme, where LAPSUS$ compromised systems and then redirected traffic to Elsevier’s internal resources, effectively gaining unauthorized access. The attack underscores the continued effectiveness of LAPSUS$, a group known for targeting high-profile organizations with a focus on exploiting vulnerabilities in Microsoft systems. The incident highlights the vulnerability of large organizations to sophisticated attacks and the importance of proactive security measures. The attack also serves as a reminder of the ongoing need to address vulnerabilities in Microsoft products, a common target for LAPSUS$.