Utopia Tech
HealthcareAI-assisted2 min read

Clinical Trial Data Stolen in Novo Nordisk Cyberattack

Novo Nordisk, the pharmaceutical company behind Ozempic and Wegovy, disclosed a cyberattack that resulted in the theft of clinical trial data affecting both patients and healthcare providers. While patient data was pseudonymized (using random ID numbers rather than names), the breach exposed limited health information including biomarkers and lifestyle factors. Healthcare provider contact informat

UT

Utopia Tech

June 15, 2026 · 2 min read

Share

Novo Nordisk, the Danish pharmaceutical firm behind the GLP-1 weight loss drugs Ozempic and Wegovy, has experienced a cyberattack that exposed the data of healthcare providers and patients enrolled in clinical trials. According to the company’s June 11, 2026, breach notice, a threat actor gained access to a limited number of its internal systems, and certain personal data stored on those systems was exfiltrated by the attackers.

It is currently unclear when the intrusion was detected or for how long hackers had access to its systems, and the threat group behind the attack has yet to publicly claim responsibility. The exposed data related to certain patients who took part in its clinical trials; however, the risk to those patients is limited, as the exfiltrated data was deidentified.

Patient names were not exposed; only the ID numbers used to identify specific patients participating in clinical trials. The ID numbers consist of random alphanumeric strings. Other compromised information was limited to sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors, such as BMI, whether the patient was a smoker, and information about their alcohol usage.

Novo Nordisk said that because the exposed data was pseudonymized, patients cannot be identified from the exposed information without further information from another source, therefore, patients are not believed to face any immediate risks. Patients have been advised to remain vigilant and to contact Novo Nordisk if they identify any suspicious activity that they believe may be linked to the incident.

When the attack was detected, certain systems were taken offline as a precaution while the incident was investigated, and Novo Nordisk is working to bring the systems back online safely and securely. The company said the cyberattack has had no impact on its core business operations, which remain up and running. The forensic investigation and data review are ongoing, and Novo Nordisk has yet to determine the number of individuals affected.

Certain healthcare providers have been affected by the incident, and they are currently being notified. The information stolen in the attack varies from provider to provider, and may include information such as the company name, registration number, contact email address, phone number, office location, and WhatsApp details. Since contact information has been compromised, healthcare providers are potentially at risk of phishing or social engineering attacks and should therefore remain vigilant.

The post Clinical Trial Data Stolen in Novo Nordisk Cyberattack appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content