TechNewsReel
Live

Novo Nordisk Suffers 1.3TB Data Breach via Leaked GitHub Token

The pharmaceutical giant declined a $25 million ransom after threat actor FulcrumSec stole proprietary AI models and clinical trial records.

TechNewsReel Newsroom · September 11, 2026

Pharmaceutical giant Novo Nordisk has suffered a major security breach that exposed proprietary research and sensitive clinical data. The incident, attributed to the threat actor FulcrumSec, underscores the severe risks associated with credential mismanagement in the biotech sector.

According to reports from BankInfoSecurity and TechRepublic, the attackers claimed to have exfiltrated approximately 1.3TB of data. The hackers subsequently demanded a $25 million ransom for the return of the information, a payment that Novo Nordisk reportedly declined. Following the failed negotiation, the threat actors began leaking portions of the stolen data online.

The Point of Entry

The breach began in March 2026, when attackers gained initial access to the company's IT environment. The entry point was a leaked GitHub personal access token, which granted the hackers access to internal repositories for approximately two months. This single point of failure allowed FulcrumSec to penetrate the company's infrastructure and harvest a vast array of sensitive files.

Compromised Intellectual Property

The stolen cache includes source code, proprietary research, and the company's AI and machine learning ecosystem. Most critically, the breach included clinical trial records. Ross Filipek, CISO at Corsica Technologies, noted that the most significant concern regarding the incident is the "long-tail value of clinical trial data," which can be exploited for competitive advantage or further targeted attacks.

Industry Implications

This incident highlights a critical vulnerability as the pharmaceutical industry pivots toward AI-driven drug discovery. The theft of AI models and clinical data represents a massive loss of intellectual property and poses significant risks to patient privacy. It demonstrates how a simple oversight—such as a hardcoded or leaked token—can facilitate large-scale corporate espionage against some of the world's most valuable companies.

What's Next

As FulcrumSec continues to leak data, the industry is watching for the full extent of the exposed clinical records and how this might impact Novo Nordisk's regulatory filings or competitive edge in the weight-loss and diabetes markets. While the primary entry vector has been identified, the full scope of the data's distribution across the dark web remains a primary concern for security analysts.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.