Last Update: 08/01/2026 at 3:01 PM EST

Novo Nordisk Breach Exposes Trial Data

Coverage from Scientific American, BleepingComputer, and others

Articles

28

Active Days

24

The Topic

Novo Nordisk Breach Exposes Trial Data topic image

Novo Nordisk disclosed that attackers accessed internal systems and copied non-public data from some clinical trials, including pseudonymized health, demographic, biomarker, and lifestyle information. Data linked to an undisclosed number of healthcare professionals was also reportedly exposed, including contact and workplace details. The company has taken affected systems offline, begun an investigation with external cybersecurity experts, and warned that the information could support targeted phishing or impersonation, while the full scope and breach mechanics remain unclear.

First Article: 06/11/26

Latest Article: 07/04/26

Summary

  • Unauthorized access led to external copying of non-public data from some Novo Nordisk internal systems.
  • Clinical-trial information reportedly included patient IDs, trial participation, demographics, biomarkers, health and immunogenicity data, and lifestyle factors.
  • Healthcare-professional records reportedly included names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations.
  • Novo Nordisk said direct patient identifiers such as names were not exposed and did not assess an immediate ability to identify trial participants.
  • Affected systems were taken offline temporarily while the company worked on a controlled restoration; core business operations were reported to continue.
  • The number of affected patients and healthcare professionals, the detection date, and the intrusion method remain undisclosed.
  • The exposed information may increase the risk of targeted phishing, fraudulent communications, and impersonation.

History

07/21/2026

The story is now more specific about what was exposed: the breach reportedly included more directly identifying healthcare-professional details and a broader set of trial data fields. It also clarifies that systems were taken offline temporarily and that the company still cannot yet specify the breach’s scope or method.

06/19/2026

The update mostly tightens and clarifies the breach narrative rather than changing it: Novo Nordisk now explicitly says copied patient data lacked direct identifiers, while broader reporting remains focused on privacy and compliance fallout. The main new wrinkle is that unverified attacker claims about larger theft have introduced some uncertainty, but not a confirmed new breach event.

Full History

Featured

Timeline: 24 Days

Jun 11Jun 15Jun 19Jun 25Jun 29Jul 3

Additional Articles

⭐⭐⭐⭐⭐

Claim Depot06-12-2026
Novo Nordisk reported unauthorized access to internal systems on June 11, 2026, exposing pseudonymized clinical trial data and identifiable healthcare professional contact details.
Benzinga / Vandana Singh06-17-2026
FulcrumSec claims June 1 online publication of data allegedly stolen from Novo Nordisk after asserted access beginning in March.
Insurance Business / Matthew Sellers06-16-2026
FulcrumSec threatened to sell allegedly stolen Novo Nordisk data after a $25 million ransom demand following a June 11 disclosed cybersecurity incident.
Pm360online06-11-2026
Novo Nordisk identified and investigated a June 11 security incident involving unauthorized copying of limited clinical-trial patient data from internal IT systems and coordinated with relevant authorities.
WNCY06-11-2026
Novo Nordisk reported an unauthorized external copy of some clinical trial patient information June 11 and began a probe with external cybersecurity experts in Bengaluru, India.
Security Point Break / Shaun Nichols06-16-2026
FulcrumSec claimed responsibility for a Novo Nordisk breach in Denmark, alleging 1.3TB exfiltration and extortion, as Novo Nordisk disclosed unauthorized access to non-public personal data.
WTVB06-11-2026
Novo Nordisk reported a security incident on Thursday involving unauthorized external copying of clinical trial patient information from internal IT systems.
SC World06-12-2026
Novo Nordisk disclosed a data breach after unauthorized access to internal IT systems exposed pseudonymized clinical trial and healthcare professional information.
Safestate06-15-2026
Novo Nordisk disclosed a breach in Denmark affecting clinical trial data and healthcare professional contact details, with GDPR notification obligations under EU rules.
Security Magazine06-15-2026
Novo Nordisk disclosed a clinical trials data breach in Denmark after a threat actor accessed limited internal IT systems containing deidentified patient data, triggering patient and healthcare provider notifications.
WTAQ News Talk06-11-2026
Novo Nordisk disclosed an unauthorized external copy of clinical trial patient data on Thursday, launched an investigation, and coordinated with relevant authorities.
1450 AM 99.7 FM WHTC06-11-2026
Novo Nordisk reported on June 11 that unauthorized external copying of clinical-trial patient data occurred from internal IT systems and launched an investigation.
Penligent Security Blog06-18-2026
Novo Nordisk confirmed unauthorized access to internal systems involving non-public clinical trial data and some personal data, while FulcrumSec extortion claims remained unverified in 2020s reporting.
Tech Insider07-04-2026
Novo Nordisk confirmed an IT breach involving pseudonymized clinical-trial and healthcare professional data, raising GDPR concerns in the EU.

⭐⭐⭐

1470 & 100.3 WMBD06-11-2026
Novo Nordisk reported an externally copied clinical-trial data security incident in which patient demographics and health data may have been affected, while authorities were contacted.
Yahoo Finance / Bailey Pemberton06-17-2026
Novo Nordisk disclosed a clinical-trial patient data breach and is assessing scope and regulatory implications amid GLP-1 production constraints.
MedPath Trial06-13-2026
Novo Nordisk disclosed an unauthorized access incident in which external copying exposed pseudonymized clinical trial and healthcare provider data.
Insurance Forums06-16-2026
FulcrumSec threatened to sell terabytes of alleged stolen Novo Nordisk data after a $25 million ransom demand was refused, following a June 11 cybersecurity disclosure in Denmark.
QPulse06-17-2026
FulcrumSec claimed responsibility for a Novo Nordisk breach disclosed in Denmark late last week, citing GitHub token access and large-scale exfiltration of clinical-trials-related data.
Databreachtoday06-12-2026
Novo Nordisk disclosed an IT security incident in Denmark that involved unauthorized access and external copying of pseudonymized clinical trial and healthcare provider data.
Fierce Pharma06-11-2026
Novo Nordisk reported a data breach involving unauthorized external copying of de-identified trial patient data and issued vigilance guidance during IT restoration.
Fierce Pharma06-17-2026
Novo Nordisk, in Denmark, faced extortion claims after a security incident as FulcrumSec and TheUSERS007 demanded ransom amounts.
Security Affairs / Pierluigi Paganini06-15-2026
Novo Nordisk disclosed a cybersecurity incident involving unauthorized access and personal data theft affecting clinical trial patients and healthcare providers, with patient data described as pseudonymized.
WHBL06-11-2026
Novo Nordisk said a security incident in internal IT systems involved unauthorized external copying of some clinical-trial patient data, and the company involved cybersecurity experts and authorities.
Global Banking and Finance / Barnali Pal Sinha06-11-2026
Novo Nordisk disclosed a security incident in Denmark in which unauthorized access led to external copying of non-public personal data.