Skip to content

LAPSUS$ Chapter II

1 claimLast activity:

Overview

“LAPSUS$ Chapter II” is a persona used on a public extortion-themed page staged in 2026. A Securonix analysis verified the page’s PGP signature against its published key but could not establish who controlled that key or continuity with the original 2021-22 LAPSUS$ operators. The page was staged before Elsevier web traffic was redirected to it Sept. 21, 2026; its presence at the destination does not identify who controlled Elsevier’s routing or establish an Elsevier-specific extortion or data-theft claim.

Incident claim

Elsevier web-portal hijack

Incident date: Source: otherDiscovered:

Claim details

Low-confidence association only: Elsevier web traffic was redirected Sept. 21, 2026, to a page branded “LAPSUS$ GROUP, Chapter II.” The page did not name Elsevier as a victim or claim Elsevier data, access or a ransom. It was staged before the redirect, and the group behind it and the party that altered routing are unverified. This entry records the observed actor-branded destination at the user’s direction, not a confirmed claim of responsibility or attribution.

Impacted organizations

Impacted locations

Source