Bankinfosecurity Novo Nordisk Data Breach Exploits Hardcoded GitHub Tokens
Article Content
- •FulcrumSec exploited hardcoded credentials to breach Novo Nordisk.
- •Over 1 terabyte of sensitive data was stolen, including drug data and customer records.
- •The breach was facilitated by a GitHub PAT and an Azure DevOps token.
Novo Nordisk suffered a data breach linked to the cyber extortion group FulcrumSec, which exploited hardcoded credentials found in client-side JavaScript across two subdomains. The attackers accessed over 1 terabyte of sensitive data, including experimental drug data and customer records, after gaining entry in June 2026. FulcrumSec utilized a GitHub Personal Access Token (PAT) and an Azure DevOps token, allowing them to navigate through Novo's cloud environments, including Amazon Web Services. The breach highlights the dangers of hardcoded credentials, as the attackers were able to exploit these vulnerabilities for two months before data was leaked. The group has previously targeted other organizations, showcasing a pattern of opportunistic cybercrime. Current reports indicate that the breach is ongoing, with the potential for further data exposure if not addressed. The incident emphasizes the need for better credential management and security practices in cloud environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track React2Shell and Arup Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple CVEs Expose Vulnerabilities in Cybersecurity Tools and Applications A series of vulnerabilities have been reported affecting various cybersecurity tools and applications. Notable among them is CVE-2024-51482, a blind SQL injection vulnerability in ZoneMinder, allowing attackers to execute arbitrary SQL commands on the database server. CVE-2026-22557, a path traversal vulnerability in…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…