GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
Hacking group claims major hack of Novo Nordisk and attempted $25 million extortion - Finance news and analysis from Global Banking & Finance Review
Finance

Hacking group claims major hack of Novo Nordisk and attempted $25 million extortion

Published by Global Banking & Finance Review

Posted on June 16, 2026

3 min read

· Last updated: June 16, 2026

Add as preferred source on Google

Hacking group claims major hack of Novo Nordisk and attempted $25 million extortion

By AJ Vicens

Details of the Novo Nordisk Cyberattack and Extortion Attempt

June 16 (Reuters) - A cyber extortion group claimed on Tuesday to have stolen more than a terabyte of data from pharmaceutical giant Novo Nordisk and said it is exploring selling parts of the data after unsuccessfully demanding $25 million from the company. 

Background on FulcrumSec and the Attack

FulcrumSec, a cyber extortion group that emerged in October 2025, said in a long message posted to its website that it spent more than two months in Novo Nordisk's networks stealing data. It said that data included company source code, proprietary information on released and unreleased drugs, trial data, employee, doctor and patient data, information related to company processing facilities and internal AI model information.

Novo Nordisk's Response

A Novo Nordisk spokesperson said in an email that the company "is aware of claims that data allegedly copied externally without authorisation from our systems has been published online. We take this matter seriously and maintain continued operations of our main platforms. We are in contact with the relevant authorities."

Verification and Communication Attempts

Reuters could not immediately verify the authenticity of the data posted by the hacking group.

FulcrumSec told Reuters in an email that Novo Nordisk representatives contacted the group on June 3, roughly 48 hours after the group's initial contact to unnamed company executives. The company used a random Proton Mail email address sent to email addresses that FulcrumSec used in its initial outreach, and confirmed it was the company by requesting specific files for verification only the company would know about.

Extortion Demands and FulcrumSec's Strategy

The FulcrumSec representative also said that the group would prefer not to sell data, "as open sourcing it is a more effective deterrent for future companies to avoid paying."

The Danish company disclosed a cybersecurity incident on June 11 that it said involved unauthorized access to a limited number of internal IT systems that included access to certain personal data. 

FulcrumSec said that after Novo Nordisk refused to pay $25 million, it was "exploring private sales" for some of the data related to certain drugs and other internal data.

Analysis and Industry Reaction

Thomas Willkan, head of research at cybersecurity firm Lab-1, who has closely tracked FulcrumSec, said the hacking group is "usually quite legit in terms of both their capabilities and also their claims."

Data Withheld by FulcrumSec

FulcrumSec said it would not share some of the data it stole, including information on thousands of company employees and physicians, and roughly 11,500 pseudonymised clinical trial patients.

The group said it also would withhold data related to operational technology and software used to interact with sensors and machinery at Novo Nordisk production facilities as part of its "harm-reduction strategy."

Context: Novo Nordisk and Related Reports

Novo Nordisk is known for its treatments for obesity and diabetes, notably Wegovy and Ozempic.

DataBreaches.net, a blog focused on cybersecurity, ransomware and data extortion, reported on June 15 that FulcrumSec told the blog on June 14 it gained access to Novo Nordisk's network in March, and shared purported correspondence with Novo Nordisk starting June 1 that included a list of more than 700,000 files, making up roughly 1.3 terabytes of data.

VX-Underground, a malware research and repository site, reported separately on Monday about an unnamed hacker having compromised Novo Nordisk. FulcrumSec said in its message that its attack is separate.

(Reporting by AJ Vicens in Detroit; Editing by Will Dunham)

Key Takeaways

  • FulcrumSec, active since September 2025 and known for its rapid cloud data exfiltration techniques, claims to have spent over two months inside Novo Nordisk’s systems, stealing source code, clinical trial and AI data, and personal records (moxfive.com).
  • Novo Nordisk confirmed unauthorized access on June 11 to a “limited number” of internal IT systems exposing pseudonymized clinical trial and patient data, and maintains core operations remain unaffected (techradar.com).
  • FulcrumSec initially demanded $25 million; following refusal, it is reportedly offering data related to drugs and internal operations in private sales, though it claims to withhold certain sensitive employee, physician, patient, and operational technology data as a “harm‑reduction strategy” (reddit.com)

References

Frequently Asked Questions

What happened in the Novo Nordisk data breach?
A cyber extortion group called FulcrumSec claims to have stolen over a terabyte of sensitive data from Novo Nordisk and attempted to extort $25 million.
What type of data was stolen in the Novo Nordisk hack?
The stolen data reportedly includes company source code, proprietary drug information, trial data, and sensitive employee, doctor, and patient information.
How did Novo Nordisk respond to the extortion attempt?
Novo Nordisk refused to pay the $25 million ransom demanded by FulcrumSec and disclosed unauthorized access to certain internal IT systems.
Who is FulcrumSec?
FulcrumSec is a cyber extortion group that emerged in October 2025, known for targeting organizations and demanding ransom for stolen data.
Is all stolen information from Novo Nordisk being leaked or sold?
FulcrumSec stated it would withhold some data, like employee and physician records and sensitive operational technology information, as a 'harm-reduction strategy.'

Tags

Related Articles

More from Finance

Explore more articles in the Finance category