Novo Nordisk disclosed a data breach that exposed clinical trial information — including age, sex, health details, lifestyle factors and randomized patient IDs — but said direct identifiers such as names were not included. The company has launched an investigation with external cybersecurity experts and notified authorities. A hacker group claimed responsibility, though that claim remains unverified. Experts warn that even limited breaches can be combined with other data to enable sophisticated scams; participants are urged to be vigilant.
Novo Nordisk Says Clinical Trial Data for Ozempic and Wegovy Exposed in Recent Breach

Last week, Danish pharmaceutical company Novo Nordisk — maker of diabetes and weight-loss drugs Ozempic and Wegovy — disclosed that it experienced a data breach resulting in unauthorized access to information collected for clinical trials.
What Was Exposed
According to the company’s public statement and letters to participants, the compromised records included participant age, sex, health information, lifestyle factors and randomized patient IDs. Novo Nordisk said direct identifiers, such as names, were not included in the exposed dataset.
"We therefore do not consider the incident to enable any third party to identify participants in our clinical trials," the company wrote. It added that, upon discovering the incident, it opened an investigation with external cybersecurity specialists and has informed the relevant authorities.
Claimed Responsibility And Expert Concerns
A hacker group calling itself FulcrumSec told the cybersecurity blog DataBreaches that it was behind the attack; that claim has not been independently verified. Cybersecurity experts say even limited-seeming breaches can be serious when combined with other breached data.
Nathan Wenzler, field chief information security officer at Optiv Security, warned that attackers and nation-state actors "have had years of breaches to build massive databases of personal information and can correlate additional data from new breaches to build a more detailed profile of a target."
Scope, Risks And Recommendations
It remains unclear how many participants were affected or how the intrusion occurred. Novo Nordisk’s clinical trials for Ozempic and Wegovy have involved tens of thousands of participants, and the company produces many medicines across diabetes, obesity, hormone replacement therapy and other areas.
What Participants Should Do
- Remain vigilant for phishing attempts, suspicious texts, calls or emails.
- Do not click links or call phone numbers included in unsolicited messages related to the breach.
- If you receive a message that appears to be from Novo Nordisk or another organization, contact them directly through their official website or a verified phone number.
- Report any unusual activity that could indicate fraud to your bank, the organization involved and relevant authorities.
Novo Nordisk said it launched an investigation with external cybersecurity experts and is working with relevant authorities. The company did not immediately respond to a request for comment from Scientific American.
Editor’s Note (6/16/26): This is a breaking-news story and will be updated as new information becomes available.
Help us improve.


































