Advises participants to remain vigillant, even though the hackers should not be able to identify them

Image:

Pharma giant Novo Nordisk reports breach of clinical trial data. Source: Johan Wessman / News Oresund, Creative Commons Attribution 2.0

Novo Nordisk, the Denmark-headquartered pharmaceuticals company, has reported a cybersecurity incident involving unauthorised access to its network resulting in the breach of clinical trial data.

In an update published on 11th June, the Danish pharmaceutical company said the breach affected “a limited amount of information” relating to patients participating in clinical trials, adding the attacks was confined to “limited number of internal IT systems”.

The exposed data includes patient identification numbers, year of birth, sex and health-related data, including biomarkers and lifestyle factors.

Novo Nordisk says the data was pseudonymised and that no directly identifiable information – such as patient names – was taken. This means that it should not be possible to identify individuals without access to additional data that was not compromised.

The company added that it does not believe the breach poses any immediate risk to patients but advised participants to remain vigilant and report any suspicious activity.

“Knowledge of patient identity would require access to further information, which was not part of the incident. We therefore do not consider the incident to bear any immediate risks for our patients,” it said in a press release.

The company has launched an investigation with support from external cybersecurity experts and is working with relevant authorities. As part of its response, certain internal systems were temporarily taken offline to contain the incident, with efforts ongoing to restore services “in a controlled and safe manner”.

It insisted that its core business operations, including manufacturing and supply chains, remain unaffected.

Novo Nordisk is the world’s largest supplier of insulin. Recently it has become best known for the weight loss drugs Ozempic and Wegovy.

Pharmaceutical firms are frequently targeted by threat actors because of the high-value IP that they hold, as well as clinical trial data and sensitive patient information. Last month ransomware group SpaceBears claimed to have breached Johnson and Jonson’s pharmaceutical division while in March the Lapsus$ group claimed to have stolen source code and cloud credentials from AstraZeneca.