Novo Nordisk has become the center of a major cybersecurity incident following the compromise of some internal IT systems and the alleged theft of over one terabyte of sensitive data. Against the backdrop of multimillion-dollar ransom demands and accusations of illicit disclosure of confidential information, the Danish pharmaceutical company has confirmed a cyber incident, with two hacker groups subsequently claiming different responsibilities.
The episode involves corporate data, intellectual property, clinical documentation, and information related to artificial intelligence programs developed by the producer of Wegovy and Ozempic.
THE BREACH OF NOVO NORDISK’S SYSTEMS
On June 11, Novo Nordisk announced that it had suffered a cybersecurity incident involving unauthorized access to a limited number of internal IT systems. The company later acknowledged that some non-public data, including personal data, was copied without authorization. In a statement, a company spokesperson said that the company is “aware of claims that data allegedly copied without authorization from our systems has been published online” and that the relevant authorities have been informed. The company also clarified that it has kept its main platforms operational and continues to prioritize “the security and integrity of systems and the reliable provision of products and support to patients.”
According to Novo Nordisk, there are no immediate risks to patients. The company explained that the personal information involved concerned participants in clinical trials and that such data did not directly link identifying elements to specific names. In a message posted on its website, the company nevertheless urged those affected to “remain vigilant” and report any suspicious activity related to the incident.
THE (FIRST) HACKER GROUP BEHIND THE CYBERATTACK
A few days after the incident was disclosed, the hacker group FulcrumSec claimed responsibility for the attack, stating that it had operated inside Novo Nordisk’s networks for over two months. Founded in October 2025, the group declared it had obtained about 1.3 terabytes of data spread across more than 700,000 files. According to the reconstruction provided by the hackers themselves, the initial access point was a GitHub access token discovered in March, which allowed cloning internal repositories and retrieving further authentication credentials.
FulcrumSec claims to have stolen source code, proprietary information on drugs already marketed and in development, clinical trial data, documentation concerning employees, doctors and patients, details about production facilities, and files associated with the company’s internal artificial intelligence models. Among the materials the group says it obtained are also information on the pharmaceutical candidates against obesity Amycretin and CagriSema, as well as five development programs not yet publicly announced.
THE RANSOM DEMANDS
According to information released by the hackers themselves, FulcrumSec demanded a ransom of $25 million. The group reported that Novo Nordisk representatives contacted them on June 3, about two days after the first message was sent to some company executives. After weeks of discussions, the hackers claim the company cut off communications without agreeing to the requested payment.
FulcrumSec later stated it is “exploring private sales” for part of the material obtained. In a message sent to Reuters, a group representative said that publishing the data would be “a more effective deterrent for future companies that decide not to pay.” The hackers also specified that some categories of information will not be disclosed, including those related to thousands of employees and doctors, data on about 11,500 pseudonymized patients involved in clinical trials, and operating systems used in production facilities, a choice described as part of their “damage reduction” strategy.
THE SHADOW OF A SECOND HACKER GROUP
A second group, identified as TheUSERS007, has also entered the scene. According to the specialized blog DataBreaches, the organization claimed a separate compromise of Novo Nordisk’s systems and demanded a $50 million ransom. In this case as well, the company reportedly did not accept the requested payment.
TheUSERS007 claims to have gained access to the company’s IT infrastructure using an adaptive, self-learning artificial intelligence engine called Venomware. The group also asserts it acquired sensitive data different from that stolen by FulcrumSec, although no independently verifiable details about the content of the material obtained have been provided.
THE INTEREST IN AI DATA
The attack is particularly significant due to the presence of information related to Novo Nordisk’s artificial intelligence projects. The company recently announced a collaboration with OpenAI aimed at applying AI in drug discovery, production processes, and commercial activities, with extensive integration planned by the end of 2026.
FulcrumSec claims that among the stolen data are proprietary artificial intelligence models developed internally by the company. Reuters, however, clarified that it has not been able to independently verify the authenticity of the material published by the group nor the claims regarding the full content of the stolen archive.
A SECTOR IN THE CROSSHAIRS OF CYBERATTACKS
The incident involving Novo Nordisk fits into a broader context in which the pharmaceutical and healthcare sector is increasingly exposed to cyberattacks. In recent weeks, Fierce Pharma recalls, West Pharmaceutical Services reported a ransomware attack on its systems.
In 2024, a breach affecting pharmaceutical distributor Cencora impacted over one million patients and at least 27 companies in the sector, leading to numerous class-action lawsuits and a $40 million settlement. In March, moreover, medical device manufacturer Stryker suffered a severe cyberattack attributed to a pro-Iranian group, compromising about 200,000 systems and stealing 50 terabytes of data.




