Novo Nordisk, the Danish pharmaceutical company behind blockbuster drugs Ozempic and Wegovy, has disclosed a cybersecurity incident resulting in a data breach. On June 12, 2026, the company announced that an unauthorized third party gained access to its internal IT systems and exfiltrated non-public data. The breach impacts both participants in the company's clinical trials and associated healthcare professionals (HCPs). While the data of trial participants was pseudonymized, the information related to HCPs was directly identifiable. Novo Nordisk has launched an investigation with external experts, taken some systems offline as a precaution, and is warning affected individuals to be on alert for follow-on phishing attacks.
Novo Nordisk has not released technical details about the initial access vector or the specific systems that were compromised. However, the nature of the exfiltrated data suggests the attackers likely breached systems related to clinical trial management or healthcare provider engagement.
Possible attack vectors could include:
T1566 - Phishing: A likely initial access vector to gain employee credentials.T1078 - Valid Accounts: Attackers likely used stolen credentials to move through the network.T1005 - Data from Local System: Attackers collected data from databases or file shares containing clinical trial and HCP information.T1567 - Exfiltration Over Web Service: The attackers copied and transferred the stolen data out of the network.Novo Nordisk has engaged external experts and taken some systems offline. Key response activities for any organization in this situation include:
Pharmaceutical companies handle highly sensitive and valuable data, requiring robust security controls.
Novo Nordisk re-confirms data breach, clarifying exfiltrated pseudonymized clinical trial data now includes immunogenicity data and biomarkers. Patients advised vigilance, no specific action needed.
Novo Nordisk has re-confirmed its data breach, providing slightly more specific details regarding the exfiltrated data. For clinical trial participants, the pseudonymized data now explicitly includes immunogenicity data and biomarkers, in addition to previously mentioned health metrics and lifestyle factors. The company reiterated that while healthcare professionals' contact details were exposed, patients do not need to take any specific action beyond remaining vigilant against potential phishing attempts. The overall scope and impact remain consistent with initial reports, focusing on privacy concerns and regulatory scrutiny under GDPR.
Novo Nordisk confirms breach by FulcrumSec, who exfiltrated 1.3TB of drug research, IP, and patient data via a compromised GitHub token. Company refused $25M ransom.
Novo Nordisk has confirmed the data breach was orchestrated by the cyber-extortion group FulcrumSec. The attackers claim to have maintained network access for over two months, exfiltrating 1.3TB of sensitive data, including drug research, internal AI models, source code, and records for 11,500 pseudonymized patients. The initial access vector was identified as a compromised GitHub access token. Novo Nordisk refused FulcrumSec's $25 million ransom demand, prompting the group to threaten private sales of the stolen intellectual property to competitors, significantly escalating the incident's severity and potential long-term impact.
Novo Nordisk publicly discloses the cybersecurity incident and data breach.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.