[Eoscstudents] Elsevier (Evolve) hacked
George Larson
glarson at eosc.edu
Tue Sep 22 10:13:29 CDT 2026
*What Happened*
- *The Incident:* On the evening of September 21, 2026, three major
Elsevier web addresses—www.elsevier.com, submit.elsevier.com, and
evolve.elsevier.com—experienced a brief domain hijacking incident. [1
<https://www.cloudskope.com/insights/post/is-sherpath-hacked-evolve-elsevier-redirect>,
2
<https://www.cloudskope.com/breaches/elsevier-lapsus-domain-hijack-2026>]
- *The Redirect:* For roughly two hours, visitors to these sites were
redirected to an external extortion page branded by the group LAPSUS$.
- *Unaffected Services:* The main research platform, sciencedirect.com,
was completely unaffected during the entire event.
*Current Status*
- *Resolution:* The unauthorized redirects were cleared by 10:09 PM CT
on September 21, 2026.
- *Operations:* All Elsevier domains are currently resolving normally,
and no data theft or ransomware encryption has been confirmed or claimed by
the attacker
This is what students need to do:
If you already entered your credentials on a suspicious page:
- Do not approve any unexpected Microsoft MFA prompts.
- Change your password using the Microsoft 365 login process.
- If you use the same password anywhere else, change it there as well.
- Contact IT and let us know that your credentials may have been entered
on a suspicious website.
- If possible, provide a screenshot of the page and the website address
you were redirected to.
---
*George Larson*
Chief Data Officer
Eastern Oklahoma State College
1301 W. Main St.
Wilburton, OK. 74578
glarson at eosc.edu
918.465.1710
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.onenet.net/pipermail/eoscstudents/attachments/20260922/7a19d492/attachment.html>
More information about the Eoscstudents
mailing list