Bg ShapeBg Shape
THREAT INTELLIGENCE

Novo Nordisk Data Breach – FulcrumSec Attribution

Affected Environment

Novo Nordisk cloud and DevOps infrastructure including GitHub repositories, Azure Container Registry, AWS, and Okta environments.

Threat Overview

FulcrumSec data extortion group claims 1.3TB theft of drug IP, AI models, source code, and clinical trial data.

Exposure Timeline

Initial access March 2026; over two months dwell time; data leaks began June 15, 2026.

Attack Surface

Exposed GitHub Personal Access Token in client-side JavaScript bundles, enabling private repository access and lateral cloud movement.

Technical Root Cause

Long-lived GitHub PAT embedded in public-facing frontend code; no adequate secrets scanning or rotation controls in place.

Exploitation Pathway

PAT discovery enabled repo cloning, credential harvesting, and low-and-slow exfiltration across cloud environments over months.

Operational Impact

Core operations unaffected per Novo Nordisk; manufacturing and clinical platforms reported as undisrupted.

Strategic Impact

Significant R&D pipeline exposure; proprietary AI models, drug compounds, and clinical data available for competitive exploitation.

Required Mitigation

Deprecate long-lived GitHub PATs, enforce secrets scanning in CI/CD, apply least privilege and zero-trust to DevOps environments.

Incident Response Guidance

Prepare data extortion playbooks, engage legal/regulatory teams early, enable dark web monitoring for FulcrumSec activity.

References

Reuters – Novo Nordisk cybersecurity incident disclosure, June 2026. DataBreaches.net – FulcrumSec correspondence and sample leak details. Heise Medien – FulcrumSec data leak at Ozempic manufacturer.

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image