A cyber extortion group has disclosed an additional collection of data that it alleges was stolen from the pharmaceutical giant Novo Nordisk. This release includes AI models, datasets, and research materials.
What happened
According to GovInfo Security, cyber extortion group Fulcrumsec has released a second cache of data that it claims was stolen from pharmaceutical company Novo Nordisk during a June 2026 cyberattack. The latest leak allegedly contains the company’s enterprise artificial intelligence and machine learning ecosystem, including models and datasets hosted through Hugging Face.
According to Fulcrumsec, the “Stage 2” release contains 30 AI models, 70 datasets, and approximately half a terabyte of proprietary cell-painting microscopy images. The group claims the full release amounts to approximately 1.05 terabytes of data.
The leak follows an earlier data release in which Fulcrumsec claimed to have exposed Novo Nordisk’s source code, drug compounds, and manufacturing information. The group had previously claimed that it stole approximately 1.3 terabytes of data from the pharmaceutical company and demanded $25 million in ransom.
The backstory
The latest leak follows a cyber incident that Novo Nordisk disclosed in June 2026. On June 11, the pharmaceutical company confirmed that attackers had gained unauthorized access to a limited number of internal IT systems and copied certain non-public data externally. The affected information was connected to participants in ongoing and past clinical trials and could include health, demographic, and immunogenicity data.
Novo Nordisk launched an investigation with external cybersecurity experts and notified relevant authorities. As a precaution, the company temporarily took some internal systems offline, although it said its core operations remained unaffected. The company also said the clinical trial dataset did not appear to contain direct identifiers such as participants' names or contact details.
Go deeper: Novo Nordisk investigates cyberattack exposing clinical trial data
Going deeper
Fulcrumsec claimed that it initially gained access through secrets allegedly exposed in client-side JavaScript on two separate Novo Nordisk subdomains. The group further alleged that it was able to access cloud services and repositories and remained undetected for extended periods. These technical claims have not been independently confirmed by Novo Nordisk, so they should be treated as allegations rather than established facts.
Furthermore, Fulcrumsec itself described the distinction between the two releases in terms of Novo Nordisk's research process. The group claimed its first release exposed the company's compounds, manufacturing recipes, and source code, while the second allegedly exposes the “machines and datasets” used to develop new products.
Novo Nordisk has said its investigation is continuing to determine whether patients and other individuals' data was affected and how many people may be involved.
What was said
According to GovInfo Security, Fulcrumsec claims that it received ‘“a good deal of interest” from Chinese buyers for the data; however, “ultimately, after consultation with friends of ours, we decided that open sourcing the data was preferable to letting some lab in Suzhou skip a decade of R&D for a few million dollars.”
They also stated that their “Stage 1 release gave the world Novo's compounds, their manufacturing recipes, and their source code. Stage 2 gives the world the machines and datasets used to create new ones.”
Fulcrumsec criticized Novo Nordisk for not properly monitoring its website's code, stating that “It remains astonishing to us, even now that we have seen this pattern again and again, that a $400 billion corporation with a dedicated cybersecurity division cannot be bothered to monitor their frontend bundles.”
In the know
According to Malpedia, “FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics.” Established in October 2025, Advisary Wire notes that “FulcrumSec’s operational model is notable for its simplicity. No zero-day exploits, no phishing infrastructure, no ransomware encryptors.”
The group has demonstrated its ability to target large organizations across different industries. In February 2026, FulcrumSec reportedly breached Avnet and exfiltrated 1.3 TB of data, including customer information, internal communications, and vendor data, demonstrating the group’s ability to target large enterprises. In April 2026, the group reportedly stole 300 GB of employee and customer data from HR platform youX, highlighting the risks of third-party providers and how a single breach can expose data belonging to multiple organizations.
Why it matters
Cybercriminals may opt to publicize stolen data to pressure victims into paying a ransom, prove that a breach occurred, damage the organization’s reputation, or make the stolen information available to potential buyers. Public leaks can also increase pressure through regulatory scrutiny, customer concerns, and reputational damage.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQS
What is the difference between ransomware and data extortion?
Ransomware typically involves encrypting systems or files and demanding payment for their recovery. Data extortion focuses on stealing sensitive information and threatening to publish or sell it.
What can healthcare organizations learn from this incident?
Healthcare and life sciences organizations should protect not only patient information but also research data, AI systems, source code, cloud environments, and intellectual property. They should also monitor third-party access and ensure that sensitive credentials and data are properly secured.
