The cyber extortion group FulcrumSec accessed Novo Nordisk’s networks in March 2026, stealing over one terabyte of data after spending more than two months inside the company systems [1]. The stolen information includes source code, proprietary data on released and unreleased drugs, clinical trial information for approximately 11,500 pseudonymised patients, employee, physician, and patient details, company processing facility data, and internal AI model information [2, 1].

FulcrumSec made a $25 million ransom demand to Novo Nordisk but the pharmaceutical company refused to pay [2, 1]. After the failed demand, FulcrumSec announced in mid-June it plans to pursue private sales of portions of the stolen data [2, 1]. A FulcrumSec representative said, “Open sourcing it is a more effective deterrent for future companies to avoid paying,” underlining their intent to pressure companies not to comply with ransom requests [2].

Novo Nordisk disclosed the breach on June 11, reporting unauthorized access to a limited set of internal IT systems, including some personal data [2, 1]. A company spokesperson said, “We take this matter seriously and maintain continued operations of our main platforms. We are in contact with the relevant authorities,” reflecting ongoing cooperation with law enforcement [2].

FulcrumSec has stated it will withhold some sensitive information, such as data on thousands of employees, physicians, the pseudonymised clinical trial patients, and operational technology systems, to reduce harm [1]. FulcrumSec first contacted Novo Nordisk representatives around June 3, approximately 48 hours after initially reaching out to company executives [2].

Cybersecurity researcher Thomas Willkan, head of research at Lab-1, commented, “FulcrumSec is usually quite legit in terms of both their capabilities and also their claims,” lending credibility to the group’s statements about the breach [2]. DataBreaches.net reported on June 15 that FulcrumSec confirmed network access dating back to March [1].

Novo Nordisk continues to investigate the incident while maintaining normal platform operations and cooperating with authorities [2, 1]. The extortion group’s next steps involve seeking private buyers for the stolen data after their ransom demand was refused [2, 1].