Novo Nordisk hit by cyber incident, probes data breach - Finance news and analysis from Global Banking & Finance Review
Finance

Novo Nordisk hit by cyber incident, probes data breach

Published by Global Banking & Finance Review

Posted on June 11, 2026

2 min read

· Last updated: June 11, 2026

Add as preferred source on Google

Novo Nordisk flags patient data breach from some clinical trials in cyberattack

Details of the Novo Nordisk Cybersecurity Incident

Overview of the Security Breach

June 11 (Reuters) - Novo Nordisk said on Thursday it has identified a security incident in which certain information, including patient data from some clinical trials, was copied externally without authorization from its internal IT systems.

Company Response and Investigation

The company, maker of the blockbuster weight-loss drug Wegovy, said it has launched a probe with the assistance of external cybersecurity experts and is in contact with the relevant authorities.

Scope of Data Affected

"The incident affected a limited amount of information related to patients participating in some of our clinical trials," Novo said in its statement, without disclosing what type of trials.

Types of Personal Data Involved

The potential categories of personal data affected may include patient ID, year of birth, sex and health or immunogenicity data among others, it added.Novo did not provide further details when contacted by Reuters.

Patient Identification and Privacy Concerns

In its statement, Novo said the information is not directly linked to any patients by name or other direct identifiers, and it does not consider the incident to enable any third party to identify participants in its clinical trials.

Knowledge of patient identity would require access to further information, which was not part of the incident, the company added.

Impact on Patients and Business Operations

The drugmaker said it does not view the incident as posing any immediate risks to patients, but advised that they report any unusual occurrences they believe could be linked to the incident.

The company has temporarily taken certain internal IT systems offline, and is working to bring the affected systems back online in a controlled and safe manner.

The company's core business operations are not impacted and remain up and running, it added.

(Reporting by Sriparna Roy in Bengaluru; Editing by Shilpi Majumdar and Leroy Leo)

Key Takeaways

  • Novo Nordisk confirmed a cybersecurity incident involving unauthorized access to internal IT systems and data exfiltration, including personal information, and is working with external experts and authorities to investigate and remediate the breach.
  • Affected internal systems have been temporarily taken offline and are being restored in a controlled, safe manner; the company emphasized that its core business operations continue uninterrupted.
  • This incident adds Novo Nordisk to a growing trend of cyberattacks targeting pharmaceutical and healthcare companies in 2026, following notable breaches such as Inotiv in December 2025 and others affecting millions of patient records globally (securityweek.com)

References

Frequently Asked Questions

What happened at Novo Nordisk?
Novo Nordisk identified a security incident involving unauthorized access to some internal IT systems.
What type of data was affected in the breach?
Certain non-public data, including personal data, was copied externally without authorization.
Are Novo Nordisk’s core business operations impacted?
No, the company's core business operations remain unaffected and continue to operate.
How is Novo Nordisk responding to the cyber incident?
The company is investigating with external cybersecurity experts, contacting authorities, and informing impacted parties.
Have any IT systems been taken offline?
Yes, some internal IT systems have been temporarily taken offline as a precaution.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category