
Novo Nordisk, a leading global pharmaceutical company, said that a recent cyber security incident exposed sensitive personal data of individuals participating in its clinical trials.
Novo Nordisk is a Denmark-based pharmaceutical company headquartered in Bagsværd. The company develops and manufactures medicines for chronic diseases, with a primary focus on diabetes, obesity, and rare endocrine disorders. It is best known for its insulin products and GLP-1-based treatments for diabetes and weight management.
In a data security incident published on its website, Novo Nordisk said it recently detected suspicious activity within its internal network that impacted a limited number of IT systems, allowing threat actors to gain unauthorised access to certain personal data stored on those systems. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
An investigation revealed that the incident affected a limited amount of information related to patients participating in some of Novo Nordisk’s clinical trials.
“This information is not directly linked to any patients by name or other direct identifiers. Information about identity would therefore require access to underlying information, identifying patients by name etc. This information was not exposed. We therefore do not consider the incident to enable any third party to identify participants in our clinical trials,” Novo Nordisk said.
The compromised data included patient IDs, gender, years of birth, biomarkers, health/immunogenicity data, lifestyle factor data and more.
The company added that, because the exposed data was pseudonymised and no additional identifying information was compromised, patient identities could not be readily determined. It therefore does not believe the incident poses any immediate risk to patients.
The incident also prompted Novo Nordisk to take the affected systems offline. While the company is working to restore them in a controlled and secure manner, it said it is currently unable to provide a timeline for when the systems will be fully operational again.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on Novo Nordisk. The company also did not share details on who was behind the attack, how much data was compromised, or whether it had received a ransom demand.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543