logo

One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.

ID: 4ac95b13-5b09-5ae8-8104-2697f50bad1d

STIX ID: report--4ac95b13-5b09-5ae8-8104-2697f50bad1d

Feed Name: DataBreaches.Net

Threat Score
78/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Dissent

...
...

Two separate threat actors — FulcrumSec and a previously unseen group calling themselves TheUSERS007 — claim to have breached Novo Nordisk and exfiltrated valuable intellectual property, with TheUSERS007 alleging theft of 16.7 GB of AI model weights, full source code, SSH keys, training data and configurations. Both groups attempted negotiations and issued multi-million-dollar ransom demands; Novo Nordisk publicly disclosed a breach on June 11 and appears to have ceased direct communications. Resecurity notes actor overlap is common and some stolen data may also be accessible from cloud storage, but the primary impact described is loss of proprietary AI and development assets rather than OT or bulk clinical records.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.