Overview
- Novo Nordisk disclosed an IT security incident that involved unauthorized access to a limited set of internal systems and exposure of certain personal data, with the company first announcing the issue on June 11.
- The firm says clinical-trial records taken were pseudonymized, meaning names were not included, but the files contain patient IDs, birth year, biomarkers and lifestyle data that could aid targeted phishing or re‑identification when linked with other data.
- Healthcare-provider contact details appear to have been copied in an identifiable form, creating immediate risks of malicious calls, texts, emails and WhatsApp-based scams against doctors and clinics.
- The extortion group FulcrumSec has claimed responsibility, said it spent months inside systems after exploiting a GitHub token, alleged it exfiltrated about 1.3 terabytes and demanded $25 million before threatening leaks or private sales; independent verification of the full haul is pending.
- Novo Nordisk has engaged external cybersecurity experts, notified authorities, taken containment steps while keeping production running, and investigators are working to confirm whether proprietary drug research, source code or AI models were actually taken and what that would mean for competitiveness and patient safety.