[Eoscstudents] Elsevier (Evolve) hacked

George Larson glarson at eosc.edu
Tue Sep 22 10:13:29 CDT 2026


*What Happened*

   - *The Incident:* On the evening of September 21, 2026, three major
   Elsevier web addresses—www.elsevier.com, submit.elsevier.com, and
   evolve.elsevier.com—experienced a brief domain hijacking incident. [1
   <https://www.cloudskope.com/insights/post/is-sherpath-hacked-evolve-elsevier-redirect>,
   2
   <https://www.cloudskope.com/breaches/elsevier-lapsus-domain-hijack-2026>]
   - *The Redirect:* For roughly two hours, visitors to these sites were
   redirected to an external extortion page branded by the group LAPSUS$.
   - *Unaffected Services:* The main research platform, sciencedirect.com,
   was completely unaffected during the entire event.



*Current Status*

   - *Resolution:* The unauthorized redirects were cleared by 10:09 PM CT
   on September 21, 2026.
   - *Operations:* All Elsevier domains are currently resolving normally,
   and no data theft or ransomware encryption has been confirmed or claimed by
   the attacker





This is what students need to do:



If you already entered your credentials on a suspicious page:

   - Do not approve any unexpected Microsoft MFA prompts.
   - Change your password using the Microsoft 365 login process.
   - If you use the same password anywhere else, change it there as well.
   - Contact IT and let us know that your credentials may have been entered
   on a suspicious website.
   - If possible, provide a screenshot of the page and the website address
   you were redirected to.









---

*George Larson*

Chief Data Officer

Eastern Oklahoma State College

1301 W. Main St.

Wilburton, OK. 74578



glarson at eosc.edu

918.465.1710
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.onenet.net/pipermail/eoscstudents/attachments/20260922/7a19d492/attachment.html>


More information about the Eoscstudents mailing list