Novo Nordisk
Incident posture
Linked entities
- Victim
- Novo Nordisk
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Novo Nordisk experienced a cyberattack that resulted in the exfiltration of data from internal systems used for clinical trials. The stolen information included deidentified patient identifiers consisting of random alphanumeric strings along with sex, year of birth, biomarker, health and immunogenicity data, and lifestyle factors such as BMI, smoking status, and alcohol usage; patient names were not exposed. Healthcare provider details such as company name, registration number, contact email, phone number, office location, and WhatsApp information were also compromised. Affected systems were taken offline as a precaution while the company works to restore them securely, and core business operations continue uninterrupted. An ongoing forensic investigation has not yet determined the total number of individuals impacted, and the responsible threat group has not been identified.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 11, 2026, Novo Nordisk issued a breach notice stating that a threat actor had gained access to a limited number of its internal systems and exfiltrated certain personal data stored on those systems. The notice did not specify when the intrusion was detected or for how long the attackers had maintained access, and the threat group responsible has not publicly claimed responsibility for the attack. Novo Nordisk, the Danish pharmaceutical company known for producing the GLP‑1 weight‑loss drugs Ozempic and Wegovy, confirmed that the breach affected data related to clinical trials.
The exfiltrated patient data consisted of deidentified information, including random alphanumeric patient ID numbers, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors such as body mass index, smoking status, and alcohol usage. Because patient names were not included and the data were pseudonymized, Novo Nordisk stated that individuals could not be identified from the exposed information without additional data from another source, and therefore patients were not believed to face any immediate risk. The company advised patients to remain vigilant and to contact Novo Nordisk if they noticed any suspicious activity that might be linked to the incident. Upon detection, certain internal systems were taken offline as a precautionary measure while the incident was investigated, and Novo Nordisk reported that it is working to restore those systems safely and securely. The company emphasized that the cyberattack has had no impact on its core business operations, which continue to function normally.
In addition to patient data, the breach exposed information belonging to certain healthcare providers who participated in the trials; the specific data varied by provider but could include the company name, registration number, contact email address, phone number, office location, and WhatsApp details. Novo Nordisk is currently notifying the affected providers and warned that the compromise of contact information could increase their susceptibility to phishing or social engineering attempts, advising them to remain vigilant. The forensic investigation and data review are ongoing, and Novo Nordisk has not yet determined the total number of individuals whose information was accessed in the attack.
Sources
Sources available to members: 1 source.