Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical LiteLLM Supply Chain Flaw Exposes 2,500 Companies, 434,000 CI/CD Pipelines
August 11, 2026
CISA Warns of Critical SonicWall SMA 1000 Zero-Days Exploited in Ransomware Attacks
August 11, 2026
Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
August 11, 2026
Home/CyberSecurity News/Novo Nordisk Confirms Data Breach After Cyberattack
CyberSecurity News

Novo Nordisk Confirms Data Breach After Cyberattack

Key Takeaways Pharmaceutical giant Novo Nordisk confirmed a cyberattack resulting in the exfiltration of pseudonymized patient data from clinical trials. The breach exposed patient IDs, health data,...

Jennifer sherman
Jennifer sherman
June 16, 2026 3 Min Read
88 0

Key Takeaways

  • Pharmaceutical giant Novo Nordisk confirmed a cyberattack resulting in the exfiltration of pseudonymized patient data from clinical trials.
  • The breach exposed patient IDs, health data, and lifestyle factors, but no direct personal identifiers like names. Healthcare professionals’ contact information was also compromised.
  • A group named Dragonfly claimed responsibility, alleging a much larger data theft, including proprietary AI models and source code, which Novo Nordisk has not corroborated.

Novo Nordisk Confirms Data Breach, Pseudonymized Patient Data Exfiltrated

Danish pharmaceutical powerhouse Novo Nordisk, widely recognized for its blockbuster weight-loss medications Ozempic and Wegovy, has publicly acknowledged a cyberattack that led to unauthorized access and data exfiltration from its internal IT systems. The incident, disclosed on June 11, 2026, involved the copying of “certain non-public data, including personal data,” from a limited subset of the company’s network infrastructure.

Table Of Content

  • Key Takeaways
  • Novo Nordisk Confirms Data Breach, Pseudonymized Patient Data Exfiltrated
  • Scope of Compromised Data
  • Dragonfly Group Claims Extensive AI and Source Code Theft
  • Company Response and Mitigation Efforts
  • What You Should Do

Scope of Compromised Data

The breach specifically impacted patient information linked to several ongoing clinical trials. The categories of data exposed include unique patient identifiers (random alphanumeric strings), gender, year of birth, various biomarkers, health and immunogenicity data, and lifestyle metrics such as BMI, smoking habits, and alcohol consumption.

Crucially, Novo Nordisk emphasized that no direct personal identifiers, such as patient names, were compromised. In an official statement, the company clarified, “Based on the nature of the exposed data as pseudonymized, knowledge of patient identity would require access to further information, which was not part of the incident.” Despite the absence of direct identifiers, the company has advised affected individuals to exercise vigilance, though it does not foresee immediate risks to patients.

Beyond patient data, healthcare professionals (HCPs) were also affected. Their exposed information includes names, professional registration numbers, email addresses, phone numbers, WhatsApp details, and office locations.

Dragonfly Group Claims Extensive AI and Source Code Theft

A threat group identifying itself as Dragonfly has stepped forward, claiming responsibility for the breach. This group alleges a significantly more extensive intrusion than Novo Nordisk has confirmed. Screenshots purportedly shared by Dragonfly suggest the theft of highly sensitive proprietary assets, including:

  • A 16.7 GB trained AI model checkpoint named NovoPert, described as an internal multimodal model encompassing text, image, and transcriptomics data.
  • A 407 MB proprietary biological/chemical training dataset.
  • The complete source code, approximately 50 MB, which includes files such as modeling_novopert.py, train.py, and the full training pipeline.
  • Logs from 113 training runs.
  • Internal infrastructure maps detailing High-Performance Computing (HPC), Slurm, and SSH configurations.
  • Over 53 GB of container images.
  • Developer identities, internal hostnames, and a private GitHub repository URL.

Novo Nordisk has been compromised. Novo Nordisk has confirmed the compromise.

Novo Nordisk is the company that became famous after producing weight loss drugs like Ozempic and Wegovy

The Threat Actor(s) responsible for the attack has been playfully extorting Novo Nordisk… pic.twitter.com/8eukIzLmvZ

— vx-underground (@vxunderground) June 15, 2026

Novo Nordisk has not corroborated these specific claims made by the Dragonfly group. At present, no particular ransomware strain has been associated with this incident.

Company Response and Mitigation Efforts

In response to the attack, Novo Nordisk has temporarily taken the compromised IT systems offline. The company has engaged external cybersecurity experts to conduct a thorough assessment of the breach’s full scope and impact. Relevant regulatory authorities have been notified. Novo Nordisk is actively working to restore the affected systems in a “controlled and safe manner.” The company confirmed that its core business operations, including drug manufacturing and distribution, remain unaffected and fully operational.

What You Should Do

  • If you are a patient involved in a Novo Nordisk clinical trial, monitor communications from the company and remain vigilant for any suspicious activity, despite the pseudonymized nature of the exposed data.
  • If you are a healthcare professional whose contact details were exposed, be particularly wary of phishing attempts, unsolicited communications, or social engineering schemes targeting your professional information.
  • Implement multi-factor authentication on all professional and personal accounts, especially those linked to your exposed email or phone numbers.
  • Regularly review and update privacy settings across all online platforms and professional networks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCybersecurityHackerransomwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

State-Sponsored AI Evades Bot Detection, Mimics Humans

Next Post

Interlock and Rhysida Ransomware Groups Share Supper Backdoor

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Daybreak Cyber Adds GPT-5.6 for Exploit Validation and Pentesting
August 11, 2026
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us