← Novo Nordisk

2026 Novo Nordisk — IT security incident; clinical trial patient data copied (investigation ongoing)

2026 Unknown records affected Share on X

Data compromised

Pseudonymized clinical-trial patient data per company notice: patient IDs, trial participation, sex, year of birth, biomarkers, health/immunogenicity data, lifestyle factors (BMI, smoking, alcohol); direct names/identifiers not exposed per Novo Nordisk

Technical writeup

On June 11, 2026 Novo Nordisk A/S published an official incident update stating it identified an IT security incident involving unauthorized access to a limited number of internal IT systems, with certain non-public data—including personal data—copied externally without authorization. The Danish drugmaker (maker of Wegovy and Ozempic) said the exposure affected a limited amount of information related to patients participating in some clinical trials; potential fields include pseudonymized patient IDs, sex, year of birth, biomarkers, health/immunogenicity data, and lifestyle factors such as BMI, smoking, and alcohol use. Novo Nordisk stated the data was not directly linked to patients by name or other direct identifiers and that knowledge of identity would require separate underlying records that were not part of the incident; the company does not consider the event to enable third parties to identify trial participants and published a patient letter stating no specific action is required. Core business operations remain running while certain internal systems were temporarily taken offline; victim totals had not been published at initial disclosure.

Root cause

Unauthorized access to limited internal IT systems; external copy of non-public data including personal data (investigation ongoing)

References