Elsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect Campaign
Executive Summary
Sorami Consulting reports that users and systems attempting to connect to Elsevier Evolve, Sherpath, and ClinicalPharmacology APIs are being redirected to extortion splash pages linked to the threat actor LAPSUS$. The redirects target domains such as lapsus.ar.io and lapsus.bz. The campaign has affected academic and medical institutions, causing exam and simulation charting disruptions, and represents a new form of API hijacking used for extortion.
Intelligence Metadata - Source Publisher: DataBreaches.net - Published Date: 2026-09-22T21:30:01+00:00 - Category: threat-intel
Original Description: Sorami Consulting reports: Users and systems trying to connect to Elsevier Evolve, Sherpath, and ClinicalPharmacology are being redirected to extortion splash pages tied to LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit is dominated by nursing and medical students locked out of exams and simulation charting, the real blast radius... Source
"Do not be embarrassed by your mistakes. Nothing can teach us better than our understanding of them. This is one of the best ways of self-education."
— Thomas Carlyle