Novo Nordisk·Healthcare·
Non-public data was copied externally.
Novo Nordisk confirmed unauthorized access to internal systems and copying of non-public clinical-trial data; a later extortion claim remains separate. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- Incident occurred
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: Secrets left in client-side JavaScript without adequate protection
- Consequence
- Reported: Non-public data was copied externally.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Novo Nordisk
- Industry
- Healthcare
- Disclosed
- Event date
- Affected asset
- internal IT systems
- Product / vendor
- GitHub
- Country
- DK
- Data involved
- Business Confidential · Credentials · Health Data · Source Code
- Reported impact
- Data exposure · Operational disruption
- Attached evidence
- 9 independent domains · 9 sources
2)Evidence-backed incident path
- 01
Reported cause
Secrets left in client-side JavaScript without adequate protection
ConfidenceSecondaryExact excerpt
E1“secrets left in client-side JavaScript”
hipaajournal.com · Jun 18 - 02
Affected product
GitHub
ConfidenceSecondaryExact excerpt
E2“using a single GitHub access token”
darkreading.com · Jun 18 - 03
Reached
internal IT systems
ConfidencePrimaryExact excerpt
E3“a limited number of internal IT systems”
novonordisk.com · Jun 18 - 04
Observed
Non-public data was copied externally.
ConfidenceProbableExact excerpt
E4“certain non-public data, including personal data, were copied externally”
globenewswire.com · Jun 11
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- Whether a ransom payment was made
- That a Defence review would have prevented this incident
4)Relevance to your product
One durable credential can carry yesterday's access into today's product.
This pattern applies when…
- Products that use GitHub access tokens to reach internal systems or repositories.
- Teams that test token scope, secret exposure, revocation, and recovery.
Diagnostic questions
- Can a client bundle, repository or response reveal a production secret?
- Does one leaked token provide more reach than its task requires?
- Can exposed credentials be identified, isolated and rotated quickly?
This incident does not establish your product's risk.
5)Sector context — Healthcare
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 1 incident threads
- 24 incident threads
- 18 incident threads
- 32 incident threads
- 26 incident threads
- 27 incident threads
- 74 incident threads
- 61 incident threads
- 28 incident threads
- Same incident family
- 16 Credential / identity compromise
- Confirmed share
- 60% 177 confirmed · 116 reported
- Display family
- Credentials Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Healthcare in Radar →6)Defence control mapping
What Defence can test
Secret exposure testing
- Can a client bundle, repository or response reveal a production secret?
- Does one leaked token provide more reach than its task requires?
- Can exposed credentials be identified, isolated and rotated quickly?
Also relevant: Identity and session testing
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
9 attached sources across 9 independent domains. At least one primary source is attached.
- E4globenewswire.comNovo Nordisk A/S: IT Security incident at Novo NordiskOther public report · Jun 11 · CitedOther public reportCited
Exact excerpt
“temporarily taking certain internal IT systems offline”
- E1hipaajournal.comHackers Claim Responsibility for Novo Nordisk CyberattackOther public report · Jun 18 · CitedOther public reportCited
Exact excerpt
“clinical trial information, intellectual property”
- E2darkreading.comNovo Nordisk Breach Exposes Software Development Pipeline RiskSpecialist reporting · Jun 18 · CitedSpecialist reportingCited
Exact excerpt
“The stolen information included source code”
- E3novonordisk.comIncident updateOrganization statement · Jun 18 · PrimaryOrganization statementPrimary
Exact excerpt
“Health/immunogenicity data”
Show all 9 sourcesShow the first six sources
Can the same secret path exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.