DEFENCE / RADAR

Public snapshot

Novo Nordisk·Healthcare·

Non-public data was copied externally.

Novo Nordisk confirmed unauthorized access to internal systems and copying of non-public clinical-trial data; a later extortion claim remains separate. The attached record does not establish the complete downstream scope.

Report freshness and timeline

Incident occurred
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: Secrets left in client-side JavaScript without adequate protection
Consequence
Reported: Non-public data was copied externally.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Novo Nordisk
Industry
Healthcare
Disclosed
Event date
Affected asset
internal IT systems
Product / vendor
GitHub
Country
DK
Data involved
Business Confidential · Credentials · Health Data · Source Code
Reported impact
Data exposure · Operational disruption
Attached evidence
9 independent domains · 9 sources

2)Evidence-backed incident path

  1. 01

    Reported cause

    Secrets left in client-side JavaScript without adequate protection

    ConfidenceSecondary
    Exact excerpt

    secrets left in client-side JavaScript

    hipaajournal.com · Jun 18
    E1
  2. 02

    Affected product

    GitHub

    ConfidenceSecondary
    Exact excerpt

    using a single GitHub access token

    darkreading.com · Jun 18
    E2
  3. 03

    Reached

    internal IT systems

    ConfidencePrimary
    Exact excerpt

    a limited number of internal IT systems

    novonordisk.com · Jun 18
    E3
  4. 04

    Observed

    Non-public data was copied externally.

    ConfidenceProbable
    Exact excerpt

    certain non-public data, including personal data, were copied externally

    globenewswire.com · Jun 11
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • Whether a ransom payment was made
  • That a Defence review would have prevented this incident

4)Relevance to your product

One durable credential can carry yesterday's access into today's product.

This pattern applies when…

  • Products that use GitHub access tokens to reach internal systems or repositories.
  • Teams that test token scope, secret exposure, revocation, and recovery.

Diagnostic questions

  1. Can a client bundle, repository or response reveal a production secret?
  2. Does one leaked token provide more reach than its task requires?
  3. Can exposed credentials be identified, isolated and rotated quickly?

This incident does not establish your product's risk.

5)Sector context — Healthcare

293 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 0 incident threads
  4. 1 incident threads
  5. 24 incident threads
  6. 18 incident threads
  7. 32 incident threads
  8. 26 incident threads
  9. 27 incident threads
  10. 74 incident threads
  11. 61 incident threads
  12. 28 incident threads
Same incident family
16
Credential / identity compromise
Confirmed share
60%
177 confirmed · 116 reported
Display family
Credentials
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Healthcare in Radar →

6)Defence control mapping

What Defence can test

Secret exposure testing

  • Can a client bundle, repository or response reveal a production secret?
  • Does one leaked token provide more reach than its task requires?
  • Can exposed credentials be identified, isolated and rotated quickly?

Also relevant: Identity and session testing

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

9 attached sources across 9 independent domains. At least one primary source is attached.

  1. E4
    globenewswire.comNovo Nordisk A/S: IT Security incident at Novo NordiskOther public report · Jun 11 · Cited
    Other public reportCited
    Exact excerpt
    temporarily taking certain internal IT systems offline
  2. E1
    hipaajournal.comHackers Claim Responsibility for Novo Nordisk CyberattackOther public report · Jun 18 · Cited
    Other public reportCited
    Exact excerpt
    clinical trial information, intellectual property
  3. E2
    darkreading.comNovo Nordisk Breach Exposes Software Development Pipeline RiskSpecialist reporting · Jun 18 · Cited
    Specialist reportingCited
    Exact excerpt
    The stolen information included source code
  4. E3
    novonordisk.comIncident updateOrganization statement · Jun 18 · Primary
    Organization statementPrimary
    Exact excerpt
    Health/immunogenicity data
  5. S5
    beyondmachines.netNovo Nordisk Discloses Cyberattack and Theft of Clinical Trial Patient DataOther public report · Jun 12 · Attached
    Other public reportAttached
  6. S6
    hackersradar.comNovo Nordisk Confirms Data Breach After Cyberattack – Hackers NewsOther public report · Jun 16 · Attached
    Other public reportAttached
Show all 9 sourcesShow the first six sources
  1. S7
    getcyberbrief.comPharma Cyber Alert: Novo Nordisk Exfiltration Without Ransom | GetCyberBriefOther public report · Jun 16 · Attached
    Other public reportAttached
  2. S8
    news.ssbcrack.comNovo Nordisk Reports Cybersecurity Incident Involving Unauthorized Access to Personal Data - SSBCrack NewsOther public report · Jun 16 · Attached
    Other public reportAttached
  3. S9
    paubox.comFulcrumsec leaks Novo Nordisk’s alleged AI and ML ecosystemSpecialist reporting · Aug 20 · Attached
    Specialist reportingAttached

Can the same secret path exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →