Danish pharmaceutical giant Novo Nordisk has confirmed a cyberattack that resulted in unauthorized access to limited non-public information, including sensitive patient health data from clinical trials and potentially high-value proprietary AI assets.
The company, globally recognized for its blockbuster GLP-1 drugs Ozempic and Wegovy, identified the breach on June 11–12, 2026, following unauthorized access to a limited number of its internal IT systems.
Novo Nordisk immediately launched an investigation with external cybersecurity experts and has since notified the relevant regulatory and law enforcement authorities.
Core pharmaceutical operations, including drug production and supply chains, remain fully functional and unaffected.
Novo Nordisk Confirms Cyberattack
According to Novo Nordisk’s official disclosure, the data copied during the incident belongs to patients enrolled in select clinical trials and includes pseudonymized patient IDs, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors such as BMI and smoking.
The company was careful to clarify that no full names or direct personal identifiers were part of the exposure, meaning re-identification of any individual would require access to separate underlying information that was not compromised.

Novo Nordisk assessed the immediate risk to patients as low given the pseudonymized nature of the records, though it recommended that patients remain vigilant and report any suspicious activity.
Beyond patient data, a threat actor published a detailed breakdown of allegedly stolen AI and machine learning assets from Novo Nordisk’s internal research infrastructure.
The exfiltrated materials reportedly include a 16.7 GB multimodal model checkpoint capable of processing text, image, and transcriptomic data, and approximately 407 MB of proprietary biological and chemical training datasets.
Roughly 50 MB of complete source code, including model classes and training pipeline logic for an internal tool referred to as NovoPert, and full logs from 113 training runs are offered as proof of authenticity.
The attackers also claimed access to internal HPC infrastructure maps, Slurm scheduling configurations, SSH settings, internal container images totaling approximately 53 GB, developer identities, and private GitHub repository URLs.
Novo Nordisk has not confirmed or denied the authenticity of these AI asset claims. The theft of AI assets carries particularly significant implications given Novo Nordisk’s broader technology strategy.
The company has heavily invested in building Denmark’s first AI supercomputer and actively deploys artificial intelligence across drug discovery, molecular design, and clinical trial optimization.
The attackers are now reportedly attempting to extort Novo Nordisk, with the stolen data potentially being sold to rival firms should the company decline to pay.
The incident underscores an increasingly dangerous dual-threat attack pattern combining clinical data exfiltration with deep intellectual property theft targeting AI research pipelines, making pharmaceutical and biotech organizations among the highest-priority targets for sophisticated threat actors in 2026.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.