Overview
- Novo Nordisk confirmed on June 11 that unauthorized access had occurred and said it is keeping core systems running while working with authorities and security teams.
- The hacking collective FulcrumSec says it spent more than two months inside Novo Nordisk networks and exfiltrated over one terabyte of data including source code, drug research, study results and internal AI models.
- FulcrumSec says Novo Nordisk refused a $25 million ransom and the group is now seeking buyers or may publicly release parts of the dataset, though it claims it will withhold some highly sensitive items.
- A 250 GB sample posted by the group and security firm commentary make the attackers’ claims appear credible, raising real risks to intellectual property and to the privacy of roughly 11,500 pseudonymized study participants.
- If material is sold or published, regulators and patients could face legal and privacy consequences, companies may need to change drug-development plans to protect trade secrets, and observers will watch whether supply and production controls remain secure.