Data breach
Novo Nordisk
- Records
- 22,812
- Breach date
- 16 June 2026Estimated
- Added
- 19 June 2026
What was exposed
6 types of data · 2 more reported
- Email addresses22,812
- Names20,972
- Phone numbers1,839
- Licence plates213
- Dates of birth40
- Street addresses3
- GenderReported, not counted
- Medical recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A cyber extortion group calling itself FulcrumSec has claimed responsibility for stealing a large volume of data from Novo Nordisk, the Danish pharmaceutical company best known for making Ozempic and Wegovy. According to our investigation team, the listing contains 22,812 records indexed with a connection to the incident, with an estimated attack date of June 16, 2026. The group says it demanded $25 million from the company, and Novo Nordisk has confirmed unauthorized access to some internal IT systems, including certain personal data. Reuters reported the claim on June 16, 2026, but could not verify the authenticity of the data the group posted. Novo Nordisk says it has not paid a ransom.
Breach Timeline
Early March 2026: FulcrumSec says it gained initial access to Novo Nordisk's networks through a GitHub access token, an account it gave to SecurityWeek. This claim comes from the group and has not been independently confirmed.
June 1, 2026: The group says it contacted unnamed Novo Nordisk executives to open extortion talks, per its account reported by Reuters.
June 3, 2026: FulcrumSec says a Novo Nordisk representative contacted the group and verified the company's identity by requesting files only the company would recognize, according to Reuters.
June 11, 2026: Novo Nordisk publicly disclosed an IT security incident involving unauthorized access to a limited number of internal systems, including certain personal data. The company said clinical trial data exposed in the incident was pseudonymized.
June 15 and 16, 2026: FulcrumSec began leaking files and posted its claim on its leak site. SecurityAffairs and Reuters covered the publication.
What Information Was Compromised?
Our analysis found the following data types in this breach: 22,812 email addresses, 20,972 names, 1,839 phone numbers, 213 vehicle plate numbers, 40 dates of birth, and 3 street addresses.
Novo Nordisk's own notice adds detail the catalog does not cover. The company said the incident affected a limited amount of information on patients in some of its clinical trials, including randomly assigned patient IDs, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors such as body mass index, smoking, and alcohol use. The company said this data is not directly linked to patients by name or other direct identifiers, and that the underlying identifying information was not exposed. For healthcare providers, however, the company said names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations may have been taken, and none of that is pseudonymized.
FulcrumSec claims a far larger haul, including source code repositories, drug compound structures, clinical trial records, and internal AI models. The company has not confirmed those broader claims.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
For employees and healthcare providers whose names, emails, and phone numbers were exposed, targeted phishing is the most immediate risk. Criminals can use real names and job details to craft convincing messages that look like internal company correspondence or legitimate medical communication. Phone numbers open the door to smishing and voice phishing. Dates of birth, vehicle plates, and street addresses, where present, can support identity fraud or more personalized scams. Clinical trial patients face less direct exposure because the company says the trial data is pseudonymized, though FulcrumSec claims it holds roughly 11,500 pseudonymized patient records. Proposed class action lawsuits have already been filed in New Jersey federal court by a former employee and a patient, according to BankInfoSecurity.
What Is Novo Nordisk Doing in Response?
The company disclosed the incident on June 11, 2026, and said in a statement to Reuters that it takes the matter seriously, maintains continued operation of its main platforms, and is in contact with the relevant authorities. It has not commented on FulcrumSec's specific claims about stolen intellectual property, and it has not paid a ransom.
What Should You Do If You Were Affected?
Be alert to phishing emails and texts that reference Novo Nordisk, clinical trials, or your workplace. Do not click links in unexpected messages, and verify requests through known contacts. Watch your accounts for unusual sign-ins and change passwords you reuse. If you received a notice from the company, follow its instructions. Beware of cold calls that know your name and employer; hang up and call back through official channels.
In the news
- Reuters: Hacking group claims major hack of Novo Nordisk and attempted $25 million extortionreuters.com (opens in a new tab)
- SecurityWeek: Cybercrime Group Claims Novo Nordisk Hacksecurityweek.com (opens in a new tab)
- SecurityAffairs: FulcrumSec Targets Novo Nordisk, Leaks Clinical and Research Datasecurityaffairs.com (opens in a new tab)
- BankInfoSecurity: Lawsuits Already Getting Filed in Drug Maker's Data Theftsbankinfosecurity.com (opens in a new tab)
