Cybercriminals demand $25 million ransom from Novo Nordisk after month‑long breach, highlighting growing ransomware threats to major biotech firms
Executive summary: Hackers infiltrated Novo Nordisk’s networks over a two‑month period and demanded a $25 million ransom following a cyber‑attack. The breach poses reputational, operational and regulatory risks for one of the world’s largest diabetes device manufacturers and could affect investor confidence in the sector.
Who is involved: Novo Nordisk, the unidentified hacker group, Danish cyber‑crime authorities and potentially international law‑enforcement agencies.
Likely next: Authorities will likely launch a formal investigation, Novo Nordisk may issue a public statement on mitigation steps, and the incident could trigger heightened scrutiny of cybersecurity practices across the pharmaceutical industry.
According to the Handelsblatt report, hackers infiltrated Novo Nordisk’s internal networks for over two months before demanding a $25 million payment. Danish authorities have been alerted and are working with law‑enforcement to investigate the breach. The incident underscores the increasing vulnerability of large pharmaceutical companies to cyber‑extortion.
Timeline
- — Erpressung: Cyberkriminelle fordern nach Angriff auf Novo Nordisk offenbar 25 Millionen Dollar (Handelsblatt)
Analysis — what this means
Likely next events
- Law enforcement initiates a formal investigation into the breach
- Novo Nordisk announces enhanced cybersecurity measures and possibly a public incident response
Sectors affected
- Pharmaceuticals
- Biotech
- Healthcare
Regulatory implications
- Mandatory breach notification to data‑protection authorities
- Possible fines for inadequate cybersecurity under EU GDPR
- Increased regulatory scrutiny of critical‑infrastructure operators in pharma
Historical parallels
- Colonial Pipeline ransomware attack (2020)
- Kaseya VSA attack (2021)
- MOVEit data‑theft breach (2023)
Key entities
Sources
Open the full interactive case file on Beyond →