
Danish pharmaceutical company Novo Nordisk, the world's leading insulin manufacturer, has reported a data breach that exposed patient information from certain clinical trials.
Established in 1923, Novo Nordisk currently has approximately 67,900 staff members across 80 offices globally and produces the widely-used GLP-1 receptor agonist drugs Wegovy and Ozempic.
On Thursday, the company announced that attackers infiltrated its internal IT systems, accessing data on patients involved in some clinical trials. This data included patient IDs (random alphanumeric strings), details on trial participation, sex, year of birth, biomarkers, health and immunogenicity information, as well as lifestyle factors such as smoking, alcohol consumption, and BMI.
Novo Nordisk emphasized that the data was pseudonymized and cannot be used by the attackers to identify any affected patients by name.
"Our investigation and response are still underway, and we have found that certain non-public data, including personal data, was copied externally without authorization. We are notifying the affected parties as appropriate," the company stated.
"This information is not directly tied to any patients by name or other direct identifiers. Identifying individuals would require access to underlying information, such as names. That information was not compromised. Therefore, we do not believe this incident enables any third party to identify participants in our clinical trials."
The breach also impacts an unspecified number of healthcare professionals (HCPs), whose names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations were exposed.
Novo Nordisk has advised affected HCPs to remain cautious of unexpected messages or calls, as they could be targeted in phishing attacks via email, phone, WhatsApp, or fraudulent messages posing as colleagues.
The company has taken the compromised internal IT systems offline but noted that its core business operations remain unaffected. Novo Nordisk is currently investigating the incident with the assistance of external cybersecurity experts to determine the full impact and scope of the breach.
"We are working to restore the affected systems in a controlled and secure manner; however, we recognize that this process will take time. Our core business operations are not impacted and continue to function normally," Novo Nordisk added.
Novo Nordisk has not yet disclosed when the breach was detected or how many individuals had their personal and patient data exposed.
When BleepingComputer contacted Novo Nordisk for further details on the attack, a company spokesperson directed us to the company's press release.
Update June 12, 06:28 EDT: Added Novo Nordisk's response.
Test every layer before attackers do
Security teams detect 54% of successful attacks and alert on only 14%. The rest go unnoticed in your environment.
The Picus whitepaper demonstrates how breach and attack simulation tests your SIEM and EDR rules to prevent threats from slipping through detection.
Related Articles:
Over 73,000 French government employees affected in Tchap messenger breach
French government messaging service breached in account hijacking attack
7-Eleven confirms data breach claimed by the ShinyHunters gang
GitHub links repo breach to TanStack npm supply-chain attack
Home security giant ADT data breach affects 5.5 million people