All Breaches
June 11, 2026 Verified Sensitive Record Pharmaceuticals

Novo Nordisk 2026 Data Breach

The Novo Nordisk 2026 data breach is an incident in which the Danish pharmaceutical company confirmed unauthorized access to a limited number of internal IT systems and the unauthorized external copying of certain non-public information, including personal data. The incident affected pseudonymized information concerning patients in some clinical trials and contact and professional information for some healthcare professionals. The company issued a public statement and separate notices on June 11, 2026.

Novo Nordisk's press release, incident update, and linked patient and healthcare-professional letters are primary sources, while BleepingComputer independently reported the details. The company did not disclose the exact dates of initial access, discovery, or copying, or the number of affected people. LeakData therefore uses June 11 as a verified public-disclosure reference and keeps pwnCount at zero to represent an unknown total.

Unauthorized Access and Data Copying

The company said the event involved a limited number of internal IT systems and unauthorized access to certain personal data stored on them. While the investigation continued, it also confirmed that some non-public data had been copied externally without authorization. “Copied externally” is a stronger exfiltration finding than possible access alone, but the number of files, data volume, and technical method were not disclosed.

Novo Nordisk did not identify the actor, initial-access vector, accounts used, possible ransom demand, or specific products and research systems involved. Ransomware, a named vulnerability, credential theft, and state sponsorship therefore are not added as facts. The verified scope is access to internal systems and unauthorized external copying of specified information.

Clinical-Trial Patient Data

Affected patient categories include a random alphanumeric patient ID and trial-participation information, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors such as smoking, alcohol use, and body-mass index. Novo Nordisk emphasized that not every category necessarily applied to every patient. These fields remain sensitive in a medical-research context and are listed separately in the data classes.

Novo Nordisk said the data was pseudonymized and not directly linked to patient names or other direct identifiers. Identifying a participant by name would require access to underlying linkage information that was not exposed. The company therefore did not consider the incident to enable third-party identification of clinical-trial participants and saw no immediate patient risk, while still recommending vigilance and reporting of anything unusual.

Healthcare-Professional Data

The official healthcare-professional letter confirms that a limited amount of non-sensitive HCP data was copied. The categories are names and professional registration numbers, email addresses, phone numbers, Whatsapp details, and office locations. The letter says not every listed category necessarily applied to every healthcare professional. The pseudonymization protecting patient data does not apply to these direct HCP contact fields.

Novo Nordisk identified targeted phishing by email, telephone, or WhatsApp and fraudulent communications impersonating colleagues as possible consequences. Healthcare professionals were advised to remain alert to unexpected messages and calls and report suspicious activity to the company. Verifiable details such as a registration number or office location can make fraudulent outreach appear more credible.

Scope Boundaries

Patient names and other direct identifiers were not part of the exposed clinical-trial information, and Novo Nordisk said the underlying linkage data needed to identify a patient was not exposed. Healthcare-professional names and contact details, however, were explicitly affected. These findings must not be conflated: “names were not exposed” applies to trial patients and does not remove the HCP name class.

Novo Nordisk did not publicly enumerate fields concerning employees, customers, or vendors; broad references to stakeholder data do not prove that each group was affected. The number of trials, country list, and person count were also undisclosed. The company's global workforce or patient reach cannot be used as a breach total. LeakData records only the published patient and HCP fields.

The Company's Response

Novo Nordisk said it launched an investigation with external cybersecurity specialists and contacted the relevant authorities after learning of the incident. It temporarily took certain internal IT systems offline to protect the environment and began returning them in a controlled and safe manner. The company said it was informing impacted parties as appropriate based on the investigation.

Core business operations were not affected and remained running. That finding describes service continuity and does not negate the confirmed copying of data. Novo Nordisk acknowledged that safely restoring affected systems would take time. Because the public update described the investigation and response as ongoing, LeakData does not assume that every system had returned or that eradication was complete.

How to Interpret This LeakData Record

This record documents two data populations in one incident: pseudonymized clinical-trial fields not directly tied to patient names and direct professional and contact information for healthcare professionals. A zero affected-person value means no verified total was published, not that nobody was affected. The company's view that patient re-identification was not enabled does not change the finding that health-related data was externally copied.

The verified conclusion is that a limited number of internal systems were accessed, non-public personal data was copied externally, some trial patients' pseudonymized health and lifestyle fields were involved, and some HCP names, registrations, contacts, and locations were affected. Patient names and linkage data were not exposed, and core operations continued. Exact timing, person count, and attack method remain undisclosed.

0
Affected Accounts
13
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

13
Pseudonymous patient ids
Clinical trial participation
Sex
Years of birth
Biomarkers
Health and immunogenicity data
Lifestyle factors
Healthcare professional names
Professional registration numbers
Email addresses
Phone numbers
Whatsapp details
Office locations

Additional Information

Added DateJuly 26, 2026
Breach DateJune 11, 2026
Domainnovonordisk.com
SourceInternal IT systems data exfiltration
Last Content UpdateJuly 26, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information