Novo Nordisk disclosed a cyberattack that exposed data from its clinical trials.
The pharmaceutical company behind Ozempic and Wegovy said attackers accessed clinical trial records. The company framed the damage as contained: the data was pseudonymous, stripped of direct patient identifiers, and in the company's own phrasing "apparently" cannot be linked to real individuals. That word, apparently, came from Novo Nordisk's own characterization of the breach.
Clinical trial data is among the most sensitive material a pharmaceutical company holds, covering experimental drug outcomes and detailed patient health responses. Pseudonymization is a standard protective measure, not an airtight one: researchers have repeatedly demonstrated that pseudonymous datasets can be re-identified when cross-referenced with other available data sources. Novo Nordisk's global profile, built on the extraordinary demand for its weight-loss and diabetes drugs, makes it a high-value target for anyone looking to monetize or exploit proprietary pharmaceutical research.
Healthcare and pharma have become reliable hunting grounds for ransomware operators and state-linked threat actors alike. "The data appears safe" has a poor track record as a closing statement.
