Extortion Gang Leaks Novo Nordisk's 'AI and ML Ecosystem'
Data Breach TodayArchived Aug 14, 2026✓ Full text saved
Fulcrumsec Claims 2nd Data Dump Exposes Firm's Hugging Face Models, Drug R&D Data Extortion gang Fulcrumsec has leaked on its dark web site a second large cache of data it allegedly stole in a June attack on Novo Nordisk. The latest data dump allegedly includes the Danish drug maker's "complete enterprise Hugging Face artificial intelligence and machine learning ecosystem."
Full text archived locally
✦ AI Summary· Claude Sonnet
Artificial Intelligence & Machine Learning , Data Privacy , Data Security
Extortion Gang Leaks Novo Nordisk's 'AI and ML Ecosystem'
Fulcrumsec Claims 2nd Data Dump Exposes Firm's Hugging Face Models, Drug R&D Data
Marianne Kolbasuk McGee (HealthInfoSec) • August 13, 2026
Credit Eligible
Get Permission
Extortion gang Fulcrumsec claims it's now leaked "the complete enterprise Hugging Face AI and ML ecosystem" it allegedly stole in a data theft attack on drug maker Novo Nordisk. (Image: Fulcrumsec)
Extortion gang Fulcrumsec has leaked on its darkweb site a second large cache of data the group claims it stole in a June attack on Novo Nordisk. The latest data dump allegedly includes the Danish drug maker's "complete enterprise Hugging Face artificial intelligence and machine learning ecosystem."
See Also: How Skilled Attackers Weaponize AI Faster
In a post Wednesday, Fulcrumsec claimed it was releasing "all of the Novo Nordisk data not included" in an earlier data dump. That latest "Stage 2" leak allegedly includes 30 Hugging Face AI models, 70 datasets and half of a terabyte of proprietary cell painting microscopy images, the gang claimed.
"1.05 terabytes in total, available via torrent for now, with additional mirrors coming soon," the Fulcrumsec group posted.
Fulcrumsec claims it received "a good deal of interest" for the data from buyers in China, but "ultimately, after consultation with friends of ours, we decided that open sourcing the data was preferable to letting some lab in Suzhou skip a decade of R&D for a few million dollars."
"Our Stage 1 release gave the world Novo's compounds, their manufacturing recipes, and their source code. Stage 2 gives the world the machines and datasets used to create new ones."
The darkweb post continues with a lengthy list specifying what the gang claims is contained in the latest leak of stolen data, including Novo Nordisk research and intellectual property pertaining to obesity, diabetes, fertility, liver disease, and other medical conditions and potential therapies.
"We gained initial access through secrets left in client-side JavaScript on two separate unrelated Novo Nordisk subdomains - two completely different teams, two different applications, the same elementary mistake made twice," the gang boasted. "We had never seen this sort of double leakage, discovered just days apart."
"It remains astonishing to us, even now that we have seen this pattern again and again, that a $400 billion corporation with a dedicated cybersecurity division cannot be bothered to monitor their frontend bundles," Fulcrumsec sneered.
"That they could not detect unknown IPs raiding their cloud services for weeks and months before responding - or never detecting us at all, in the case of their HuggingFace and Okta accounts," the post said.
Novo Nordisk did not immediately respond to ISMG's request for comment on Fulcrumsec's claims.
The drug maker on June 11 acknowledged it was hacked, stating that it had identified and was investigating an security incident involving unauthorized access "to a limited number of internal IT systems" (see: Hackers Begin to Leak Novo Nordisk's Stolen Data).
In addition to Fulcrumsec's claims, in June, a second hacker group, TheUSERS007, told Databreaches.net that it too stole "crown jewel" data - including AI models - from the maker of popular diabetes and weight loss treatment drugs Ozempic and Wegovy.
Fulcrumsec on its leak site acknowledges that other group's claims. "It has come to our attention that another actor has claimed a breach of Novo Nordisk simultaneously. Based on what we have been told, it sounds potentially legitimate, even though the post appears to be entirely AI slop from a cheap chatbot," Fulcrumsec said. "Even if real, they are claiming something like 18 GB; we have 1.3 TERABYTES. And they are not claiming the patient or doctor PII, which precipitated Novo's disclosure; that was us."
Novo Nordisk in mid-June said its ongoing investigation discovered that "certain non-public data, including personal data, was copied externally without authorization. We are informing the impacted parties as appropriate."
Fulcrumsec also claimed on its leak site to have healthcare professional and clinical personnel personally identifiable information that has not been leaked and is "withheld per agreement." That data allegedly includes information pertaining to 46,843 Danish healthcare professionals, 506,007 clinical investigators, and 2,852 named clinical trial personnel.
Novo Nordisk in its latest statement said it is still investigating whether patient and other individuals' data was affected, and how many.
Rising Threats
If confirmed, the theft of Novo Nordisk's AI models and intellectual property and research demonstrates the evolving threats and risks that life sciences and similar bio technology firms face, some experts said.
These latest extortion attempts pose risks such as giving competitors unfair advantages, counterfeiting products, compromising patient privacy and creating biosecurity risks, said attorney Lee Kim, founder of consulting firm Keytera, and former longtime cybersecurity and privacy principal at the Healthcare Information and Management Systems Society. Novo Nordisk and other breached firms have some legal protections, she said.
"Organizations whose intellectual property is stolen in a cyberattack may seek injunctions prohibiting its use or disclosure, request takedowns of publicly posted material, notify recipients that the information was unlawfully obtained, pursue civil and criminal remedies and take steps to block the sale or importation of products developed using the stolen IP," Kim said.
But those steps may not be enough in the face of increasingly sophisticated attacks.
"You can set the bar higher for protecting the data but that doesn't ensure that an attacker won't be able to defeat your protections," she said. IP-related data "should not be low-hanging fruit," she said.
Organizations must carefully inventory and protect IP and AI models, she stressed. "Make it harder for attackers to get in. Vigilantly monitor insider and external threats," she said.
"Be vigilant about data protection with appropriate administrative, physical and technical safeguards."
Novo Nordisk is already facing multiple proposed class action lawsuits involving the alleged data theft incidents (see: Lawsuits Already Getting Filed in Drug Maker's Data Thefts).