June 5, 2026
Danish pharmaceutical giant Novo Nordisk, the maker of popular weight loss drug Wegovy, disclosed two ransomware incidents where the threat actors were seeking $25 million in one attack, and $50 million in the other.
In the second attack “TheUSERS007,” said they were going to leak stolen data after ransom negotiations with Novo Nordisk failed.
Those threat actors claim to have acquired between June 5-7 some different data than what FulcrumSec shared in the first attack. Both threat groups appeared to have been negotiating with Novo Nordisk at the same time.
Data incident site, DataBreaches, asked TheUSERS007 how they gained access to Novo Nordisk and the answer is frightening. In a chat on Tox, a spokesperson for TheUSERS007 told DataBreaches they used venomware.
Venomware is an emerging, highly advanced class of digital attack tool classified as a self-learning, adaptive AI engine used to surgically extract intellectual property. Unlike traditional malware, it does not typically break into systems using forced exploits or encryption; rather, it uses artificial intelligence to identify misconfigurations and navigate networks. which they describe as a self-learning, adaptive AI engine designed for the surgical extraction of intellectual property.
