Danish pharmaceutical giant Novo Nordisk—maker of Ozempic and Wegovy—published an official incident update on June 11, 2026 confirming unauthorized access to a limited number of internal IT systems and external copying of certain non-public data, including personal data related to clinical trials.
What Novo Nordisk confirmed
The company said attackers copied data from internal systems without authorization. Affected information relates to patients in some clinical trials and may include pseudonymized patient IDs, sex, year of birth, biomarkers, health/immunogenicity data, and lifestyle factors (BMI, smoking, alcohol use).
Novo Nordisk emphasized that data was not directly linked to patients by name and that identifying participants would require separate underlying records that were not exposed. The company does not consider the incident to enable third parties to identify trial participants and stated no specific patient action is required.
Official patient guidance
Novo Nordisk published a patient letter recommending vigilance and asking trial participants to report anything unusual that could be linked to the incident.
What trial participants should do
- Watch for official Novo Nordisk communications—not leak-site downloads.
- Report suspicious contact referencing trial participation to the company’s privacy channels.
- Enable MFA on email accounts used for clinical trial portals.
Canonical record: Novo Nordisk 2026 on BreachHistory.
Sources: Novo Nordisk official disclosure, Reuters, HIPAA Journal