Novo Nordisk disclosed a security breach in which attackers copied non-public data from internal IT systems, including information tied to some clinical-trial participants and healthcare professionals. The exposed trial data included patient IDs, participation details, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors; the company said it was pseudonymized and not directly linked to names. Exposed healthcare professional data included names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations. Novo Nordisk has not said how many people were affected or how the intrusion happened.
Why it matters: This affects sensitive health-related research data and gives attackers contact details they can use for follow-on phishing or impersonation. Affected organizations and individuals should watch for suspicious emails, calls, and WhatsApp messages while Novo Nordisk investigates scope and attack path.
Ionut Arghire
2026.06.16
95% relevant
This article updates the same Novo Nordisk breach by adding that FulcrumSec claims responsibility, says it used a GitHub access token in March to clone repositories and obtain more credentials, alleges theft of 1.3TB and over 700,000 files including intellectual property, and says it demanded a $25 million ransom.
Eduard Kovacs
2026.06.15
98% relevant
This article is a direct report of the same Novo Nordisk breach, adding that the company says attackers accessed a limited number of internal IT systems and exposed pseudonymized clinical-trial participant data plus healthcare professional contact details, with no direct identifiers disclosed.
2026.06.12
99% relevant
This article is the same underlying event and adds concrete details about the stolen data fields: pseudonymized clinical-trial participant information, affected internal IT systems taken offline, and a separate warning that healthcare professional contact details could be used for targeted phishing via email, phone, and WhatsApp.
Sergiu Gatlan
2026.06.12
100% relevant
This article is the initial public disclosure of Novo Nordisk's breach and establishes the core facts of the incident, including the affected data types and the warning about phishing risks for healthcare professionals.
← Back to all stories