A cyber-extortion group calling itself FulcrumSec said Monday it has stolen about 1.3 terabytes of data from Novo Nordisk, the Danish company that makes the weight-loss drugs Wegovy and Ozempic , and demanded $25 million to keep it private. Novo Nordisk has not paid that amount, and the group, according to its own claims, is now looking for buyers for the data.
See also: Hacking Silence: Attacks via ultrasound and inaudible commands

FulcrumSec claims it spent more than two months inside the company’s networks before being removed. This length of time is worrisome to security professionals, as it suggests a significant breach rather than a quick theft. Its prolonged presence on Novo Nordisk suggests that the cybercriminals had the opportunity to explore and gain a deep understanding of the company’s internal processes, which may have allowed for the extraction of a large amount of data.
The group claims to have obtained a wide range of sensitive information, including source code, proprietary information for both released and unreleased drugs, clinical trial data, employee, doctor and patient records, manufacturing facility details and material related to the company’s internal AI models. This data, if indeed stolen, could have serious consequences for Novo Nordisk, as it includes critical information related to research and development, production and the protection of the privacy of the individuals involved.
Novo Nordisk confirmed that it had detected unauthorized access to certain internal IT systems and said it was responding to the incident. The company has not confirmed the volume of data claimed by FulcrumSec, nor has it independently verified the specific categories of stolen material. This uncertainty adds an additional layer of concern as Novo Nordisk must assess the full extent of the breach and take steps to protect its systems from future attacks.
See also: Russian hackers distribute GIFTEDCROOK stealer via WinRAR vulnerability

After the company refused to pay the ransom, FulcrumSec said it was looking into private sales of some of the data, including material linked to specific drugs. This development is particularly concerning, as data related to healthcare and research has enduring value in criminal markets. It can be used for fraud, identity theft and targeted phishing, meaning the consequences of a breach could be long-lasting.
FulcrumSec is a relatively new name in the cyber-extortion field, having emerged in October 2025. It follows the now-established model of double-extortion groups: infiltration, silent data extraction, and then the threat of publication. This model works because stolen healthcare and research data has lasting value in criminal markets, useful for fraud, identity theft, and targeted phishing long after the initial theft.
Refusing to pay is the option most security professionals would recommend, as paying funds the next attack and offers no real assurance that the data will be deleted. Refusing to pay means the material is likely to be leaked or sold. Novo Nordisk is currently in a difficult position, having made the defensible choice to refuse the ransom while still dealing with the consequences of the breach. If FulcrumSec is telling the truth, the stolen data is now on the market.
See also: JINX-0164 hacking group targets cryptocurrency development infrastructure

This situation highlights the growing threat of cyberattacks for healthcare and pharmaceutical research companies. These organizations must invest in strong security measures to protect their data and ensure that sensitive information does not fall into the wrong hands. The Novo Nordisk case serves as a warning to all organizations in this sector, highlighting the need for continued vigilance and a proactive approach to cybersecurity.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
