API Security
LAPSUS$ Hijacks Elsevier APIs in Targeted Extortion Campaign
Educational and clinical APIs associated with Elsevier have been compromised by the LAPSUS$ group, redirecting users to extortion-themed domains.
Understanding the API Hijacking Campaign
Recent reports indicate that the notorious threat actor group LAPSUS$ has successfully compromised several high-profile APIs, including those used by Elsevier Evolve, Sherpath, and ClinicalPharmacology. Users attempting to connect to these essential medical and educational platforms are being redirected to malicious domains designed for extortion. This incident marks a significant escalation in how threat actors target supply-chain integrations, specifically hitting critical infrastructure used by healthcare professionals and students.
Mitigation Strategies for API Integrity
To protect against similar hijacking attempts, organizations must prioritize robust API security controls. First, implement strict API Gateway authentication and ensure that redirect URI validation is enforced to prevent unauthorized rerouting. Second, adopt a zero-trust model for third-party integrations, ensuring that every service connection is continuously verified. Finally, organizations should monitor their external-facing DNS and domain records for any unauthorized modifications that could point to malicious landing pages. Regular security audits of API endpoints are essential to identifying potential misconfigurations before they are weaponized by threat actors.
แหล่งที่มา: DataBreaches.net เผยแพร่ครั้งแรก: Tue, 22 Sep 2026 21:30:01 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: DataBreaches.net
เผยแพร่ครั้งแรก: Tue, 22 Sep 2026 21:30:01 +0000
บทความต้นฉบับ: https://databreaches.net/2026/09/22/elsevier-evolve-clinicalpharmacology-and-gsdd-apis-hijacked-lapsus-redirect-campaign/
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
