Novo Nordisk
Incident posture
Linked entities
- Victim
- Novo Nordisk
- Threat actors
- 2 actors
- Sources
- 3 sources
Timeline
Summary
Novo Nordisk disclosed a cyber intrusion after hackers accessed its IT systems and copied data without authorization. FulcrumSec said it entered through a GitHub token, harvested 1.3 terabytes of source code, AI models, drug research, clinical trial files and pseudonymised patient information, then demanded a $25 million ransom that was refused. After the extortion failed the group offered the data for sale on channels, while another actor claimed a separate breach focused on AI assets. The firm stated only limited systems were affected and it is working with authorities.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 11 2026 Novo Nordisk disclosed a cybersecurity incident involving unauthorized access to a limited number of its internal IT systems that included access to certain personal data. The company stated that data had been copied externally without authorisation, including patient information. According to the disclosure, the breach was identified after the attackers had been present in the network since March 2026, initially gaining entry through a dormant access credential and later discovering additional credentials over the following two‑and‑a‑half months. The hack‑and‑leak group FulcrumSec, which emerged at the end of 2025, claimed responsibility for the intrusion, asserting that it accessed Novo Nordisk’s systems via a GitHub access token that allowed it to clone repositories and harvest further credentials. FulcrumSec said it spent more than two months inside the networks, exfiltrating roughly 1.3 terabytes of data comprising over 700 000 files and demanding a $25 million ransom from the company.
FulcrumSec asserted that the stolen material included source code, proprietary information on marketed and experimental drugs such as Amycretin and CagriSema, clinical trial data from the SELECT, FLOW, SOUL, FOCUS and ONWARDS studies, internal AI model information, details of company processing facilities, and operational technology used to interact with sensors and machinery at production sites. The group also claimed to have obtained pseudonymised information on approximately 11 500 research subjects, data on healthcare professionals, and details of company employees, noting that the pseudonymised data could not directly identify individuals without a master key. After Novo Nordisk refused the ransom demand, FulcrumSec stated it was exploring private sales of certain drug‑related and internal data and offered the exfiltrated information for sale via dark‑web channels, while indicating it would withhold employee, physician, patient‑trial and operational‑technology data as part of a harm‑reduction strategy. A separate claim of a second, unrelated breach focused on AI assets was made by an individual using the handle TheUSERS007; Novo Nordisk has not acknowledged this allegation.
In response, a Novo Nordisk spokesperson told Reuters that the company is aware of claims that data allegedly copied externally without authorisation from its systems has been published online, that it takes the matter seriously, maintains continued operation of its main platforms, and remains in contact with the relevant authorities. The company reiterated that the breach involved a limited number of internal IT systems and that the accessed patient data was pseudonymised, requiring additional information not present in the incident to identify individuals. DataBreaches.net reported that FulcrumSec shared purported correspondence with Novo Nordisk beginning June 1, including a list of more than 700 000 files, and VX‑Underground noted an unrelated unnamed hacker compromise of Novo Nordisk, which FulcrumSec described as separate from its own activity. No further details regarding the outcome of extortion negotiations, the extent of any data publication, or specific remedial actions beyond continued platform operation and authority engagement were provided in the source material.
Sources
Sources available to members: 3 sources.