Why did I receive a content protection alert email?
Last updated on March 02, 2026
We are notifying you because our system has detected suspicious activity originating from your institution. This could suggest that either an end user or an account has been compromised. Your email address is listed with us as a primary contact for these alerts.
Suspicious activities refer to any unauthorized use, distribution, or piracy of our content. This includes illegal file sharing, copyright infringement, or any other actions that violate our policies.
Legitimate Elsevier emails always:
- Come from an email address ending on @elsevier.com or a product name (e.g., @ecommerce.elsevier.com, @mendeley.com, [email protected], @editorialmanager.com, @notification.elsevier.com, @3d4medical.com)
- Feature the Elsevier logo or product wordmark on the top left side of the email
We may have blocked your institution from accessing Elsevier services because we detected suspicious activity on your account. This activity suggests that there may be unauthorized access to ScienceDirect or other Elsevier services through automation or compromised user accounts. Whenever possible, we will block individual sessions to minimize disruption. However, if we cannot identify the specific individuals involved, we may need to block access at the IP level.
Please note: If you don't take the necessary actions to stop the activities, it may take longer to restore access to the affected IP address(es). Contact the Content protection team to request support if needed.
The next steps depend on the type of alert that was triggered. This is specified in the notification emails you received.
For suspicious activity not related to Federated Authentication we provide a CSV file that contains log information for Layer 7 requests (i.e. HTTP Traffic). This file is attached to the alert email. Depending on the alert type, we also include other information, such as destination IP adresses and ports.
The following information is specified in the logfile or alert email:
Compromised user accounts can happen for various reasons, such as sharing passwords, using weak passwords, falling victim to phishing attacks, reusing credentials, outdated software, brute force attacks, inadequate security measures, and data breaches. To protect your institution from these incidents, we suggest reaching out to your CISO/IT Security department for guidance on possible solutions. They can provide you with more information and help implement measures to enhance security and prevent such incidents.
Did we answer your question?
Related answers
Recently viewed answers
Functionality disabled due to your cookie preferences