
The FulcrumSec ransomware group has leaked more than 250 GB out of 1.3 TB of confidential data that it stole from pharmaceuticals company Novo Nordisk during a cyber attack earlier this month.
Earlier this month, Novo Nordisk said it detected suspicious activity within its internal network that impacted a limited number of IT systems, allowing threat actors to gain unauthorised access to certain personal data stored in those systems. An investigation revealed that the incident affected a limited amount of information related to patients participating in some of Novo Nordisk’s clinical trials.
The compromised data included patient IDs, gender, years of birth, biomarkers, health/immunogenicity data, lifestyle factor data and more.
The company added that, because the exposed data was pseudonymised and no additional identifying information was compromised, patient identities could not be readily determined. It therefore does not believe the incident poses any immediate risk to patients.
The incident also prompted Novo Nordisk to take the affected systems offline. While the company is working to restore them in a controlled and secure manner, it said it is currently unable to provide a timeline for when the systems will be fully operational again.
Recently, a group of threat actors going by the name FulcrumSec claimed responsibility for the cyber attack on Novo Nordisk and listed the Ozempic maker as a victim on its data leak site.
According to the group, it has stolen approximately 1.3 terabytes of data stored in more than 700,000 files. According to Reuters, the group demanded a ransom of $25 million from the company and threatened to leak the stolen database unless its ransom demands weren’t met.
Following unsuccessful ransom negotiations, the hacker group released 264 GB of data and publicly accused Novo Nordisk of poor cybersecurity practices. The group said that weak passwords, including “novo123,” were used on critical systems and mocked the company’s security team.
Acknowledging the reports of the data leak, a Novo Nordisk spokesperson said that the company “is aware of claims that data allegedly copied externally without authorisation from our systems has been published online. We take this matter seriously and maintain continued operations of our main platforms. We are in contact with the relevant authorities.”
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543