Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Novo Nordisk breach lawsuits: what the complaints get wrong

Ransomnews Research TeamBy Ransomnews Research TeamOctober 3, 2026Updated:October 4, 2026No Comments18 Mins Read135 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Novo Nordisk data breach lawsuits cover: two lawsuits, one footnote. A terminal panel shows both complaints cite ransomnews.com for the 1.3 terabyte figure, plead a class of over one hundred members against a claimed 163,000 employee records, and leave the attack vector unpleaded. ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Novo Nordisk faces two proposed class actions over the FulcrumSec data breach, filed in the District of New Jersey on 17 and 18 June 2026 by a former employee and a self-described patient. Both cite one source for the breach, our 17 June report, and plead FulcrumSec’s claimed 1.3 terabytes as fact. Neither says how the attackers got in or uses the word pseudonymised.

// KEY FACTS

Threat actor
FulcrumSec
Victim
Novo Nordisk · Pharmaceuticals · Denmark
Timeline
Attack: Access from March 2026, by FulcrumSec's account  ·  Disclosed: 2026-06-11
Data claimed
claimed 1.3 TB / 700,000+ files, 264 GB leaked by 18 June · Confirmed: pseudonymised clinical-trial data, healthcare-professional contact details. Claimed: 163,000+ employee records, source code, AI models
Ransom status
$25M demanded, refused, data leaking since 15 June
Verification
Novo Nordisk confirmed unauthorised access and the trial and healthcare-professional data in its 11 June notices. The volume, the employee records and the entry point are FulcrumSec claims. Two class actions (D.N.J. 3:26-cv-07280 and 3:26-cv-07353) cite Ransomnews for the breach's scale; we reviewed both complaints as filed.

We read both complaints, twice. They are one document with the plaintiff swapped out. They plead a class of “at least one thousand” people against an attacker claim of more than 163,000 employee records, and they skip the parts of the public record that would help them most. The standing fight will turn on a question neither filing asks: whose data, exactly, did FulcrumSec take?

What do the Novo Nordisk lawsuits allege?

Both lawsuits allege that Novo Nordisk failed to protect the personal and health data of its patients and employees, and both bring the same four counts against Novo Nordisk Inc. and its Danish parent, Novo Nordisk A/S: negligence, negligence per se, breach of implied contract and unjust enrichment. Both demand a jury and define the class as “all individuals residing in the United States whose PII/PHI was compromised in the Data Breach that impacted Defendants in or around June 2026, including all those individuals who received notice of the breach.”

Picinich v. Novo Nordisk Inc. (3:26-cv-07280) came first, on 17 June. Lauren Picinich, a former employee who lives in New Jersey, says the company required “at least her name, address, Social Security number, phone number, and insurance information” as a condition of the job. Four firms signed her complaint: Carella Byrne Cecchi Brody & Agnello, Strauss Borrelli, Milberg and Kopelowitz Ostrow. Sterner v. Novo Nordisk Inc. (3:26-cv-07353) followed on 18 June from Milberg alone, for Mary Sterner of Florida. Its civil cover sheet marks Picinich as a related case before Judge Georgette Castner.

Sterner’s relationship with the company is one sentence: “Plaintiff Mary Sterner is a patient of Defendants.” Novo Nordisk makes and sells drugs rather than treating people, so patient could mean a trial participant, a patient-programme enrollee or simply a customer. The complaint never says which, or what her breach notice told her was exposed.

The two filings are one template. The breach paragraphs (18 to 26) match line for line, and so do the paragraph numbers, the class definition, the counts, footnote 1 and the injuries, down to “a spike in spam and scam phone calls”. The template shows in one place. Paragraph 43 of Sterner’s complaint, filed for a patient, says that had she known about the company’s security she “would have either (1) not worked for Defendants at all, or (2) would have required a salary premium (i.e., a ‘compensating wage differential’)”. That sentence was written for the former employee in the earlier filing. Nobody changed it.

Where did the complaints get their facts?

Both complaints got their facts about the breach from Ransomnews, and from nowhere else. Paragraph 18 reads: “In or around June 2026, Defendants were hacked by the notorious cybercriminal group FulcrumSec who exfiltrated approximately ‘1.3 terabytes and around 700,000 files’ from Defendants.” Footnote 1 cites our report, Bluebook-style, to “RANSOM NEWS”, two words. Footnote 2, under the next paragraph, reads “Id.”, the same article again. Nothing else either complaint cites is about this breach; the rest is standard data-breach furniture, from a BlackFog blog post to the FBI’s 2019 internet crime report.

The first suit was filed the day our report went up. Picinich is stamped 17 June, the date of our article, so a figure FulcrumSec posted on its leak site was in a federal complaint within a day of our reporting it.

Novo Nordisk: from intrusion to lawsuit Timeline of the Novo Nordisk breach and lawsuits, 2026: FulcrumSec says access began in March and talks opened on 1 June; Novo Nordisk disclosed on 11 June; leaking began on 15 June; the leak-site listing appeared on 16 June; the Ransomnews report and the Picinich complaint came on 17 June; the Sterner complaint on 18 June. Novo Nordisk: from intrusion to lawsuit FulcrumSec’s claim Public record Litigation March 2026: FulcrumSec says its access to Novo Nordisk began. The complaints date the breach in or around June 2026. MARCH 2026 FulcrumSec says its access began. The complaints say ‘in or around June 2026’ 1 June: FulcrumSec says it opened talks with Novo Nordisk over the stolen data. 1 JUNE FulcrumSec says it opened talks with Novo Nordisk over the stolen data 11 June: Novo Nordisk discloses the incident and writes to healthcare professionals. 11 JUNE Novo Nordisk discloses the incident and writes to healthcare professionals 15 June: with its 25 million dollar demand unpaid, FulcrumSec starts leaking data. 15 JUNE With its $25M demand unpaid, FulcrumSec starts leaking data 16 June: Novo Nordisk appears on the FulcrumSec leak site, per the Ransomnews Ransomtracker. 16 JUNE Novo Nordisk appears on FulcrumSec’s leak site, per our Ransomtracker 17 June: the Ransomnews report is published and Picinich v. Novo Nordisk is filed the same day, citing it. 17 JUNE Our report goes up. Picinich v. Novo Nordisk is filed the same day, citing it 18 June: Sterner v. Novo Nordisk is filed, citing the same report as footnote 1. 18 JUNE Sterner v. Novo Nordisk is filed, citing the same report as footnote 1 Sources: Novo Nordisk, FulcrumSec, Ransomtracker, court filings

We reported 1.3 TB and 700,000 files as FulcrumSec’s claim, and the Key Facts box on that report says “claimed” in so many words. Novo Nordisk has not confirmed a volume. The complaints quote the number, drop the qualifier and plead it as what left the network. A leak-site listing proves that a group is extorting a company. It proves nothing about what was taken, and groups round up. That gap is why we run a breach verification desk.

Paragraph 20 looks more careful. It says Novo Nordisk “has confirmed that the exposed data included at least ‘patient IDs, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors like BMI and smoking status.'” That is our sentence, word for word, minus the word that comes just before it in our report: pseudonymised. Neither complaint uses that word, or “de-identified”, or “clinical trial”, although Novo Nordisk’s own disclosure, reported by BleepingComputer, says the trial data “is not directly linked to any patients by name or other direct identifiers”. A complaint that wants to argue the data can be re-identified has to meet that point. These walk past it.

They also leave out the rest of the report they cite. It showed novonordisk.com in infostealer logs before the breach surfaced: 211 sets of employee credentials, 580 logins captured on the company’s own pages and 2,932 session cookies. We could not show that any of it was FulcrumSec’s way in, and still cannot. But for complaints alleging, on information and belief, that Novo Nordisk “failed to maintain reasonable security safeguards or protocols”, it is the closest thing to dated, observable evidence of the company’s exposure in the public record. Neither uses it.

Who is FulcrumSec?

FulcrumSec is a data-theft extortion group: it copies data, demands payment and publishes or sells what it took, and there is no public evidence that it encrypted anything at Novo Nordisk. Our Ransomtracker profile of the group holds 28 listings since October 2025, when it posted Avnet’s data with a message that the company “shouldn’t have lowballed us repeatedly”. Twenty-one listings went up in a single batch on 29 April 2026, including a re-listing of Avnet. Novo Nordisk followed on 16 June and is the biggest name on the list. The group is still active: two more names went up in September.

How did FulcrumSec get into Novo Nordisk?

FulcrumSec says it got into Novo Nordisk through credentials left in client-side JavaScript on two forgotten subdomains, and neither complaint mentions it. In statements reported by HIPAA Journal, Dark Reading and Cybersecurity Insiders, the group said one bundle held an Azure container registry credential and the other a GitHub personal access token with access to hundreds of private repositories: “two completely different teams, two different applications, the same elementary mistake made twice”. Sysdig, citing CybelAngel, named the hosts as dev.nnedl.pub.aws.novonordisk.com and datahub-sand.novonordisk.com. The group says it cloned the repositories, pulled the API tokens, database credentials and service-account passwords out of them, and spent more than two months in the network, from March to June. It adds that Novo Nordisk spotted it in GitHub after about two weeks and in Azure after three.

This is the attacker’s account, and Novo Nordisk has not confirmed it. It is specific, though, and it fits the inventory the group published, which is heavy on repositories, container images, HPC configuration and training-run logs: what a GitHub token and a registry credential reach. If it is roughly right, the complaints’ theory of fault, that Novo Nordisk “failed to adequately train their employees on cybersecurity”, aims at the wrong failure. This was secrets management, not staff training. And by the attackers’ telling the company did detect them and did not get them out, which is a different allegation from having “no effective means” to detect them.

Free tool

How does your own site score?

Run the same forty passive checks against your own domain: TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

What data was stolen in the Novo Nordisk breach?

Novo Nordisk has confirmed two data sets, and everything else comes from FulcrumSec. The first is pseudonymised clinical-trial data: a random patient ID, trial participation, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors. The second is healthcare professionals’ details, which the company’s 11 June letter lists as names and registration numbers, email addresses, phone numbers, WhatsApp details and office locations. FulcrumSec claims far more: more than 163,000 employee records, 11,500 pseudonymised trial patients, 4,750 source-code repositories, more than 30 trained AI models and 1.3 TB in all, of which 264 GB was listed for download by 18 June, according to HIPAA Journal. Novo Nordisk’s public statements do not mention employee data.

Will the plaintiffs have standing?

On the Third Circuit’s test, the former employee has a plausible claim to standing and the patient a weak one. The District of New Jersey is bound by Clemens v. ExecuPharm, 48 F.4th 146 (3d Cir. 2022), and the facts rhyme. CLOP phished its way into ExecuPharm, a Parexel subsidiary, in March 2020, stole current and former employees’ Social Security numbers, bank details and passport numbers, and published nearly 123,000 files, 162 GB, on the dark web when no ransom came. The district court dismissed the former employee’s suit for lack of standing, and the Third Circuit vacated that ruling. Courts judging whether a risk of future harm is imminent, it said, look at “whether the data breach was intentional”, “whether the data was misused” and “whether the nature of the information accessed through the data breach could subject a plaintiff to a risk of identity theft”. A plaintiff who then suffers emotional distress or pays for “mitigation measures like credit monitoring services” has a concrete injury.

The first two factors favour both plaintiffs. The theft was deliberate, the thief has a name, and the data has been misused, with 264 GB already public. The third factor splits them. Picinich’s case is Clemens with the names changed, provided she is among the 163,000 employee records FulcrumSec claims. Her complaint never cites that claim, and Novo Nordisk has not said employee data was taken. She appears to have had a breach notice, since the complaint says the company “directed Plaintiff to take those steps in their breach notice”, but the letter is not attached, dated or quoted, and it is the document that would show what was exposed.

Sterner’s case is weak. The only patient data Novo Nordisk has confirmed is the pseudonymised trial set, and the company’s statement, as quoted by The Register, says that identifying anyone in it “would therefore require access to underlying information, identifying patients by name etc. This information was not exposed.” Taken at face value, that data cannot open a credit line, and the harms she pleads, from scam calls to fear for her finances, assume identifiers the company says were never there. She would need to plead that she sits in another data set or that the trial data can be re-identified in practice. She pleads neither, and never says she was in a trial.

The cleanest injury belongs to people neither plaintiff represents: the healthcare professionals whose names, registration numbers and WhatsApp details were exposed, and whom Novo Nordisk has warned to expect “fraudulent communications impersonating colleagues”.

What do the complaints leave out?

The complaints leave out almost everything that would size the class or test their theory of fault. Set against the public record, the gaps look like this.

QuestionWhat both complaints pleadThe public record
Source for the breachRansomnews only (footnotes 1 and 2)Novo Nordisk’s notices, FulcrumSec’s leak site, trade press
How much was taken“1.3 terabytes and around 700,000 files”, as factClaimed by FulcrumSec; no volume confirmed by Novo Nordisk
Trial dataListed without the word pseudonymisedPseudonymised, per Novo Nordisk
How the attackers got inPoor staff training, on information and beliefExposed JavaScript secrets: a registry credential and a GitHub token (FulcrumSec’s account)
When“In or around June 2026”Access from March (FulcrumSec); disclosed 11 June
Who is affected“current and former patients and employees”Trial participants and healthcare professionals confirmed; employees claimed
Class size“at least one thousand”No figure from Novo Nordisk; 163,000 employee and 11,500 trial records claimed
ExtortionNot mentioned$25M demanded and refused, leaking since 15 June, a second claim by TheUSERS007
Ransomnews Research Team review of both complaints as filed, set against Novo Nordisk’s notices and FulcrumSec’s published claims.

Some of this is forgivable in complaints filed within two days of a leak-site listing, and stolen drug-discovery models are a trade-secrets problem, not a privacy one. The gaps that matter are the ones that decide standing: which data set each plaintiff is in, and whether that data can identify them.

What should affected people do?

Anyone who received a Novo Nordisk breach letter should keep it. The company is writing to each affected group separately, so the letter says which data set you are in, and both complaints define the class to include “all those individuals who received notice of the breach”.

  • Healthcare professionals: expect impersonation. Novo Nordisk’s letter warns of targeted phishing by email, phone and WhatsApp. Check any unexpected request from a Novo Nordisk contact through a number you already hold, and report it to the company, as the letter asks.
  • Current and former employees: freeze your credit. If employee records were taken, Social Security numbers are the field that matters, and Picinich says the company required hers. A credit freeze at Equifax, Experian and TransUnion is free in the US, and an IRS Identity Protection PIN blocks tax-refund fraud in your name. For continuous alerts, see our dark-web monitoring review.
  • Trial participants: the risk is scams, not identity theft. The trial data carries a random ID, not a name. Be suspicious of anyone who contacts you about your trial participation and asks for personal or payment details, and check with your trial site directly.
  • Nobody needs to sign up for anything yet. No class has been certified. Treat any message asking for a fee, or for your Social Security number, to claim Novo Nordisk breach compensation as a scam.

What happens next?

The two cases are likely to be consolidated before Judge Castner, given the related-case flag on Sterner’s cover sheet, and further suits often follow the first two. Novo Nordisk’s standard first move would be a motion to dismiss on standing and pleading grounds, and its own public line, that the trial data is pseudonymised and the risk low, is that motion in outline. Clemens gives the plaintiffs a way through only if they amend to say whose data was taken and what kind. If the cases reach discovery, they would produce what no leak site will: an inventory of what FulcrumSec actually took. We have reviewed the complaints as filed, not the later docket, and will update this article as the cases move.

What this means for breach reporting

A number from an extortion group reached a federal complaint within a day, and lost its qualifier on the way. Our report said FulcrumSec “claims it stole” 1.3 terabytes in the same sentence as the figure; the complaints kept the figure and dropped the verb. Anyone who reports on extortion should assume the same will happen to their numbers. For security teams the cheaper lesson is in FulcrumSec’s own account: scan front-end bundles for secrets before release, give tokens the narrowest scope and an expiry date, and retire sandbox subdomains instead of forgetting them.

Frequently asked questions

Who is suing Novo Nordisk over the data breach?

Two people are suing Novo Nordisk over the FulcrumSec data breach: Lauren Picinich, a former employee (Picinich v. Novo Nordisk, 3:26-cv-07280, filed 17 June 2026), and Mary Sterner, a Florida resident who describes herself as a patient (Sterner v. Novo Nordisk, 3:26-cv-07353, filed 18 June 2026). Both filed proposed class actions in the District of New Jersey.

Am I part of the Novo Nordisk class action?

You may be in the proposed class if you live in the US and your data was compromised in the breach, since both complaints define it to include “all those individuals who received notice of the breach”. No class has been certified, so there is nothing to join or pay for yet.

Where did the Novo Nordisk lawsuits get the 1.3 TB figure?

The Novo Nordisk lawsuits took the 1.3 TB figure from Ransomnews: footnote 1 of both complaints cites our 17 June 2026 report. That report gave 1.3 TB and 700,000 files as FulcrumSec’s claim, and Novo Nordisk has not confirmed a volume.

How did FulcrumSec breach Novo Nordisk?

FulcrumSec says it breached Novo Nordisk with credentials left in client-side JavaScript on two forgotten development subdomains: an Azure container registry credential and a GitHub personal access token. Novo Nordisk has not confirmed the entry point.

What data was stolen in the Novo Nordisk breach?

Novo Nordisk has confirmed the theft of pseudonymised clinical-trial data and healthcare professionals’ contact details. FulcrumSec claims much more, including 163,000 employee records, source code and AI models, none of which Novo Nordisk has confirmed.

Is pseudonymised clinical-trial data enough to sue over?

Pseudonymised clinical-trial data is a weak basis for standing in the Third Circuit, where Clemens v. ExecuPharm asks whether stolen data could expose a plaintiff to identity theft. A plaintiff relying on it would need to plead that the data can be re-identified, and neither complaint does.

How many people are affected by the Novo Nordisk data breach?

The number of people affected by the Novo Nordisk breach is unknown, because the company has not published one. FulcrumSec claims 163,000 employee records and 11,500 trial participants, while both complaints plead a class of at least one thousand.

Sources and further reading

  • Picinich v. Novo Nordisk Inc. et al., D.N.J. 3:26-cv-07280, complaint filed 17 June 2026 (PDF via ISMG)
  • Sterner v. Novo Nordisk Inc. et al., D.N.J. 3:26-cv-07353, complaint filed 18 June 2026 (PDF via ISMG)
  • Clemens v. ExecuPharm Inc., 48 F.4th 146 (3d Cir. 2022), opinion via Justia
  • Novo Nordisk: incident update and letter to healthcare professionals, 11 June 2026
  • BleepingComputer: Pharma giant Novo Nordisk discloses breach of clinical trials data, 12 June 2026
  • The Register: Novo Nordisk reports cyberattack as UK gives Wegovy pill the nod, 12 June 2026
  • HIPAA Journal: Hackers claim responsibility for Novo Nordisk cyberattack
  • Dark Reading: Novo Nordisk breach exposes software development pipeline risk, 18 June 2026
  • Cybersecurity Insiders: FulcrumSec spent two months in Novo Nordisk networks before 1.3TB theft, 22 June 2026
  • Sysdig: The FulcrumSec playbook, 25 June 2026
  • Law360: Novo Nordisk sued over data hack tied to extortionist group, 18 June 2026
  • GovInfoSecurity: Lawsuits already getting filed in drug maker’s data thefts
  • Novo Nordisk hit by FulcrumSec: the stealer logs saw it coming, our 17 June report, cited in both complaints
  • Ransomware ditched encryption in May 2026: here’s why, on the data-theft extortion model FulcrumSec runs
  • How stealer logs power modern ransomware attacks

Analysis by the Ransomnews Research Team. We reviewed both complaints as filed. Nothing in this article is legal advice.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleConti was hiring: the ransomware crew’s entrance exam
Next Article Confirmed ransomware attacks, September 2026: 55 verified so far, Qilin and The Gentlemen lead
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Conti was hiring: the ransomware crew’s entrance exam

September 17, 2026

Exploit.in: inside a Russian hacker forum, 2005 to 2008

September 17, 2026

Telegram 120M leak: we counted 63M, most from 2020

September 8, 2026

Comments are closed.

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,713 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.