CLINICAL TRIAL DATA EXPOSED
The pharmaceutical company Novo Nordisk was attacked by cybercriminals. Some data on patients participating in clinical trials was compromised. However, company representatives maintain that no harm was done to the patients. They state that the names and other direct identifiers of the trial participants were not disclosed, so outsiders—in this case, hackers or fraudsters—should not be able to link the compromised data to specific individuals.
Novo Nordisk's official statement stated that unknown attackers gained unauthorized access to a limited number of internal IT systems. During an emergency investigation, the company also discovered that some non-public information, including personal data, was copied outside the organization without authorization. This cyber incident, according to the company's official statement, affected only a limited amount of patient data from certain clinical trials. Among the possible categories of data, company representatives cite a random patient identifier, trial participation information, gender, year of birth, biomarkers, health and immunogenicity data, and certain lifestyle factors, including smoking, alcohol consumption, and body mass index. However, Novo Nordisk confidently clarifies that not all of the listed categories may have been exposed for every affected patient. The company specifically emphasizes that the client data was pseudonymized. To identify a patient, hackers would have needed access to additional information linking participants to names and other direct identifiers. However, Novo Nordisk states that such information was not stolen by the hackers in the incident. The company states that patients do not need to take any special action following the incident. Novo Nordisk does not foresee any immediate risks for trial participants. However, the company advises patients to remain vigilant and to report any unusual events that may be related to the incident. Following the discovery of the incident, Novo Nordisk cybersecurity specialists launched an internal investigation. Company representatives also promptly contacted the relevant authorities. As a security measure, the company temporarily disabled some of its internal IT systems and is now gradually bringing them back online in a controlled manner. Novo Nordisk's core operations, according to company representatives, were not affected and are continuing as usual. The number of people affected by the incident has not yet been reported. No known hacker group has yet claimed responsibility for the attack.
