Friday, June 19th, 2026 — Novo Nordisk, the pharmaceutical manufacturer behind Ozempic and Wegovy, is confronting a significant cybersecurity incident after a hacking group known as FulcrumSec claimed responsibility for stealing more than 1.3 terabytes of company data. According to the group’s account, attackers gained access to Novo Nordisk’s network in March and remained inside company systems for more than two months before demanding a $25 million ransom.
The hackers allege the stolen information includes source code, clinical trial records, employee and physician data, patient information, details about released and unreleased drugs, manufacturing-related data, and internal artificial intelligence models. After Novo Nordisk reportedly refused to pay the ransom, FulcrumSec announced plans to pursue private sales of selected data and warned that additional information could be released publicly.
For insurance claims professionals, the incident illustrates the continuing evolution of cyber extortion events. Rather than focusing solely on operational disruption, many threat actors now rely on data theft and reputational pressure to force payments. This shift can create complex claims involving privacy liability, regulatory investigations, notification costs, crisis management expenses, forensic investigations, and potential litigation from affected parties.
The case also highlights the growing exposure associated with intellectual property and research data. If proprietary pharmaceutical information or clinical trial records are ultimately released, losses could extend beyond traditional cyber response costs and into business valuation concerns, competitive harm, and shareholder-related claims. Insurers underwriting cyber, professional liability, and management liability coverages are likely to monitor developments closely.
Novo Nordisk has acknowledged unauthorized access affecting certain internal systems and stated it is working with authorities. While the authenticity and scope of the allegedly stolen data have not been independently verified, cybersecurity researchers tracking FulcrumSec have described the group as a credible threat actor. The situation remains fluid as investigators determine the full extent of the breach and any resulting liabilities.