logo

The FulcrumSec playbook: How to detect and stop the group behind the Novo Nordisk breach

ID: bca548a7-145f-57d6-9854-a536b60491a7

STIX ID: report--bca548a7-145f-57d6-9854-a536b60491a7

Feed Name: Sysdig Blog

Threat Score
78/100

Date Published: 2026-06-25

Date Updated: 2026-06-26

...
...

FulcrumSec is a financially motivated cloud-native threat actor that has claimed roughly two dozen victims (including Novo Nordisk, LexisNexis, youX, and Avnet), stealing terabytes of sensitive data by abusing exposed credentials, misconfigured cloud storage, and unpatched internet-facing applications (notably exploiting CVE-2025-55182). The report maps their playbook across initial access, credential harvesting, slow data collection and quiet exfiltration using legitimate tools, and extortion, and recommends removing secrets from code, enforcing least privilege for machine identities, accelerating patching, and deploying behavioral detections that correlate identity, cloud, and runtime activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.