Novo Nordisk Confirms Data Breach After Cyberattack
Key Takeaways Pharmaceutical giant Novo Nordisk confirmed a cyberattack resulting in the exfiltration of pseudonymized patient data from clinical trials. The breach exposed patient IDs, health data,...
Key Takeaways
- Pharmaceutical giant Novo Nordisk confirmed a cyberattack resulting in the exfiltration of pseudonymized patient data from clinical trials.
- The breach exposed patient IDs, health data, and lifestyle factors, but no direct personal identifiers like names. Healthcare professionals’ contact information was also compromised.
- A group named Dragonfly claimed responsibility, alleging a much larger data theft, including proprietary AI models and source code, which Novo Nordisk has not corroborated.
Novo Nordisk Confirms Data Breach, Pseudonymized Patient Data Exfiltrated
Danish pharmaceutical powerhouse Novo Nordisk, widely recognized for its blockbuster weight-loss medications Ozempic and Wegovy, has publicly acknowledged a cyberattack that led to unauthorized access and data exfiltration from its internal IT systems. The incident, disclosed on June 11, 2026, involved the copying of “certain non-public data, including personal data,” from a limited subset of the company’s network infrastructure.
Table Of Content
Scope of Compromised Data
The breach specifically impacted patient information linked to several ongoing clinical trials. The categories of data exposed include unique patient identifiers (random alphanumeric strings), gender, year of birth, various biomarkers, health and immunogenicity data, and lifestyle metrics such as BMI, smoking habits, and alcohol consumption.
Crucially, Novo Nordisk emphasized that no direct personal identifiers, such as patient names, were compromised. In an official statement, the company clarified, “Based on the nature of the exposed data as pseudonymized, knowledge of patient identity would require access to further information, which was not part of the incident.” Despite the absence of direct identifiers, the company has advised affected individuals to exercise vigilance, though it does not foresee immediate risks to patients.
Beyond patient data, healthcare professionals (HCPs) were also affected. Their exposed information includes names, professional registration numbers, email addresses, phone numbers, WhatsApp details, and office locations.
Dragonfly Group Claims Extensive AI and Source Code Theft
A threat group identifying itself as Dragonfly has stepped forward, claiming responsibility for the breach. This group alleges a significantly more extensive intrusion than Novo Nordisk has confirmed. Screenshots purportedly shared by Dragonfly suggest the theft of highly sensitive proprietary assets, including:
- A 16.7 GB trained AI model checkpoint named NovoPert, described as an internal multimodal model encompassing text, image, and transcriptomics data.
- A 407 MB proprietary biological/chemical training dataset.
- The complete source code, approximately 50 MB, which includes files such as
modeling_novopert.py,train.py, and the full training pipeline. - Logs from 113 training runs.
- Internal infrastructure maps detailing High-Performance Computing (HPC), Slurm, and SSH configurations.
- Over 53 GB of container images.
- Developer identities, internal hostnames, and a private GitHub repository URL.
Novo Nordisk has not corroborated these specific claims made by the Dragonfly group. At present, no particular ransomware strain has been associated with this incident.
Company Response and Mitigation Efforts
In response to the attack, Novo Nordisk has temporarily taken the compromised IT systems offline. The company has engaged external cybersecurity experts to conduct a thorough assessment of the breach’s full scope and impact. Relevant regulatory authorities have been notified. Novo Nordisk is actively working to restore the affected systems in a “controlled and safe manner.” The company confirmed that its core business operations, including drug manufacturing and distribution, remain unaffected and fully operational.
What You Should Do
- If you are a patient involved in a Novo Nordisk clinical trial, monitor communications from the company and remain vigilant for any suspicious activity, despite the pseudonymized nature of the exposed data.
- If you are a healthcare professional whose contact details were exposed, be particularly wary of phishing attempts, unsolicited communications, or social engineering schemes targeting your professional information.
- Implement multi-factor authentication on all professional and personal accounts, especially those linked to your exposed email or phone numbers.
- Regularly review and update privacy settings across all online platforms and professional networks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.