Skip to content

Elsevier web hijack disrupts Missouri nursing coursework

Legitimate Elsevier addresses sent visitors to a LAPSUS$-branded page; Boise State restricted access to a faculty platform as a precaution.

Three-story office building with an Elsevier sign and “3251” on its facade, seen across a parking lot.
Elsevier’s corporate office in Maryland Heights, Missouri. (Cushman & Wakefield)

Websites operated by Elsevier, a scientific and medical publisher that supplies nursing schools with online learning tools, redirected visitors to an outside page Monday, disrupting Missouri nursing students’ coursework.

The page displayed LAPSUS$, the name of a hacking group known for stealing data and extorting organizations. Security firm Cloudskope observed redirects from Elsevier’s Evolve learning site, main website and manuscript-submission portal for at least 78 minutes.

At Truman State University in Kirksville, nursing students trying to use Elsevier for homework landed on the branded page, KTVO reported, citing the student newspaper. Elsevier’s Evolve platform gives nursing and health-professions students access to assigned materials and study tools.

Browser displaying lapsus.ar.io above a dark “LAPSUS$ GROUP” page with a statement, a disclosed-targets panel and a countdown.
A screenshot posted to Reddit shows the LAPSUS$-branded page reached during the Elsevier redirects. The branding does not establish who was responsible for the redirects.

Grand Canyon University’s tech-support team reported an outage affecting Evolve and other Elsevier resources. At Western Governors University, nursing students reported on Reddit that they could not access Elsevier quizzes and course materials.

Elsevier said its cybersecurity team restored normal service. In a statement to Help Net Security, the company said its investigation found no indication that core platforms, customer data, research content or operational systems were compromised.

The disruption also prompted a precaution in Idaho. Boise State University told the state attorney general it disabled single sign-on to Interfolio, a faculty activity system, while reviewing the Elsevier reports. It restored access Tuesday morning and said Interfolio and university-hosted services were not affected.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

Elsevier is headquartered in Amsterdam and lists U.S. corporate offices in New York and Maryland Heights, Missouri.

Before Elsevier’s websites were redirected, cybersecurity company Securonix examined the LAPSUS$-branded page that visitors later reached. The version it reviewed showed an extortion announcement and countdown, but no form to collect passwords or code to deliver malware. Securonix could not identify who ran the page or connect them to the original LAPSUS$ group. Its findings did not establish who redirected Elsevier’s web traffic.

Elsevier has not said how the web addresses were redirected or how many visitors saw the page.

Joseph Topping

Joseph Topping

Joseph Topping is the founder and editor of DysruptionHub, reporting on cyber incidents and technology failures that disrupt public services, organizations and daily life.

All articles

More in Education

See all

More from Joseph Topping

See all