Skip to content
Novo Nordisk Data Breach Exploits Hardcoded GitHub Tokens

Novo Nordisk Data Breach Exploits Hardcoded GitHub Tokens

First seen 12 Sep 2026, 16:40 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 12, 2026 at 18:55 UTC
  • FulcrumSec exploited hardcoded credentials to breach Novo Nordisk.
  • Over 1 terabyte of sensitive data was stolen, including drug data and customer records.
  • The breach was facilitated by a GitHub PAT and an Azure DevOps token.

Novo Nordisk suffered a data breach linked to the cyber extortion group FulcrumSec, which exploited hardcoded credentials found in client-side JavaScript across two subdomains. The attackers accessed over 1 terabyte of sensitive data, including experimental drug data and customer records, after gaining entry in June 2026. FulcrumSec utilized a GitHub Personal Access Token (PAT) and an Azure DevOps token, allowing them to navigate through Novo's cloud environments, including Amazon Web Services. The breach highlights the dangers of hardcoded credentials, as the attackers were able to exploit these vulnerabilities for two months before data was leaked. The group has previously targeted other organizations, showcasing a pattern of opportunistic cybercrime. Current reports indicate that the breach is ongoing, with the potential for further data exposure if not addressed. The incident emphasizes the need for better credential management and security practices in cloud environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-01
Initial access gained by FulcrumSec
FulcrumSec exploited hardcoded credentials in JavaScript on two Novo Nordisk subdomains.
Govinfosecurity
2026-09-11
Data leak confirmed
FulcrumSec released over 1 terabyte of data after Novo Nordisk refused to pay the ransom.
Govinfosecurity
2026-09-12
Incident reported by multiple outlets
Both Govinfosecurity and Bankinfosecurity reported on the breach, confirming the details of the attack.
Bankinfosecurity

More articles in this cluster (2)

Following this threat?

Track React2Shell and Arup Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed