A cyber-extortion group calling itself FulcrumSec says it breached Novo Nordisk’s network and stole about 1.3 terabytes of data, including information related to drugs, clinical trials, employees and physicians, production systems, and internal AI model data. Several reports cite the group’s claims that it spent more than two months inside Novo Nordisk’s systems, with access beginning in March, and later described an attempted extortion scheme. FulcrumSec says it demanded $25 million and threatened to publish or sell the stolen material if the payment was not made. Multiple outlets report that Novo Nordisk did not pay the demand and that the group is exploring options including selling parts of the data, while also saying it would withhold some categories of sensitive information as part of a “harm-reduction strategy.”

Novo Nordisk, through a spokesperson quoted in one report, says it is aware of claims that data allegedly copied from its systems has appeared online and says it continues operating its main platforms. The company also says it is in contact with relevant authorities.

The reports rely on FulcrumSec’s statements and do not provide independent confirmation of the exact data contents or the full impact of the intrusion.