CSIDB logo
Incident

Novo Nordisk

Incident posture

Attack window
Jun 2026
Location
Denmark
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-14 00:16

Linked entities

Victim
Novo Nordisk
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Jun 2026
Resolved
Pending

Summary

Novo Nordisk experienced a cyberattack that resulted in the exfiltration of data from internal systems used for clinical trials. The stolen information included deidentified patient identifiers consisting of random alphanumeric strings along with sex, year of birth, biomarker, health and immunogenicity data, and lifestyle factors such as BMI, smoking status, and alcohol usage; patient names were not exposed. Healthcare provider details such as company name, registration number, contact email, phone number, office location, and WhatsApp information were also compromised. Affected systems were taken offline as a precaution while the company works to restore them securely, and core business operations continue uninterrupted. An ongoing forensic investigation has not yet determined the total number of individuals impacted, and the responsible threat group has not been identified.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 11, 2026, Novo Nordisk issued a breach notice stating that a threat actor had gained access to a limited number of its internal systems and exfiltrated certain personal data stored on those systems. The notice did not specify when the intrusion was detected or for how long the attackers had maintained access, and the threat group responsible has not publicly claimed responsibility for the attack. Novo Nordisk, the Danish pharmaceutical company known for producing the GLP‑1 weight‑loss drugs Ozempic and Wegovy, confirmed that the breach affected data related to clinical trials.

The exfiltrated patient data consisted of deidentified information, including random alphanumeric patient ID numbers, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors such as body mass index, smoking status, and alcohol usage. Because patient names were not included and the data were pseudonymized, Novo Nordisk stated that individuals could not be identified from the exposed information without additional data from another source, and therefore patients were not believed to face any immediate risk. The company advised patients to remain vigilant and to contact Novo Nordisk if they noticed any suspicious activity that might be linked to the incident. Upon detection, certain internal systems were taken offline as a precautionary measure while the incident was investigated, and Novo Nordisk reported that it is working to restore those systems safely and securely. The company emphasized that the cyberattack has had no impact on its core business operations, which continue to function normally.

In addition to patient data, the breach exposed information belonging to certain healthcare providers who participated in the trials; the specific data varied by provider but could include the company name, registration number, contact email address, phone number, office location, and WhatsApp details. Novo Nordisk is currently notifying the affected providers and warned that the compromise of contact information could increase their susceptibility to phishing or social engineering attempts, advising them to remain vigilant. The forensic investigation and data review are ongoing, and Novo Nordisk has not yet determined the total number of individuals whose information was accessed in the attack.

Sources

Sources available to members: 1 source.

CSIDB