Pharmaceutical

Industry

Novo Nordisk Suffers Second Ransomware Attack

June 5, 2026

Danish pharmaceutical giant Novo Nordisk, the maker of popular weight loss drug Wegovy, disclosed two ransomware incidents where the threat actors were seeking $25 million in one attack, and $50 million in the other.
In the second attack “TheUSERS007,” said they were going to leak stolen data after ransom negotiations with Novo Nordisk failed.
Those threat actors claim to have acquired between June 5-7 some different data than what FulcrumSec shared in the first attack. Both threat groups appeared to have been negotiating with Novo Nordisk at the same time.
Data incident site, DataBreaches, asked TheUSERS007 how they gained access to Novo Nordisk and the answer is frightening. In a chat on Tox, a spokesperson for TheUSERS007 told DataBreaches they used venomware.
Venomware is an emerging, highly advanced class of digital attack tool classified as a self-learning, adaptive AI engine used to surgically extract intellectual property. Unlike traditional malware, it does not typically break into systems using forced exploits or encryption; rather, it uses artificial intelligence to identify misconfigurations and navigate networks. which they describe as a self-learning, adaptive AI engine designed for the surgical extraction of intellectual property.

read more

Pharmaceutical Maker Novo Nordisk Suffers Ransomware Attack

March 10, 2026

Despite a cyberattack at Novo Nordisk A/S that forced the company to shut down some systems, its core business operations remain up and running.
To that end, Novo Nordisk, the maker of weight-loss drug Wegovy, said Thursday, June 11, it identified an IT security incident involving unauthorized access to a limited number of internal IT systems.
“Upon learning of the incident, we launched an investigation with the assistance of external cybersecurity experts, and we are in contact with the relevant authorities,” the company said in an advisory.

read more

Sagent Pharmaceuticals Suffers Cyberattack

February 11, 2026

Schaumburg, Illinois-based Sagent Pharmaceuticals suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“We recently discovered unauthorized access to our network occurred on or around February 11, 2026,” the company said in a notice to victims. “We immediately launched an investigation in consultation with outside cybersecurity professionals who regularly investigate and analyze these types of situations to analyze the extent of any compromise of the information on our network.”
Sagent Pharmaceuticals’ investigation and document review concluded on March 23. They discovered attackers were able to steal victims’ full name, Social Security number, driver’s license number or state identification number. Additionally, they took bank account information, and/or health insurance policy information.

read more

AstraZeneca Data For Sale after Attack

March 20, 2026

An AstraZeneca data breach linked to the LAPSUS$ threat group just appeared on a Dark Web post and it is showing a new type of ransomware attack, a threat research group said.
Based on the materials reviewed, the claim goes beyond a routine leak post and suggests possible exposure of internal code repositories, access-related data, cloud and infrastructure references, and employee-linked records, according to a report with cybersecurity threat intelligence provider, SOCRadar.
A breach involving AstraZeneca ended up advertised on a Dark Web forum and also appeared on a data leak site associated with LAPSUS$. The listing claims the attackers obtained a large archive containing internal data, including source code, infrastructure-related material, and access-linked information.

read more

Cyberattack at Pharma Product Maker, Researcher, Chiesi USA

August 28, 2025

Cary, North Carolina-based Chiesi USA, Inc., a pharmaceutical manufacturing and researcher, suffered a cyberattack in August where personally identifiable information ended up stolen in the hack.
“On August 28, 2025, we learned of potential unauthorized access to our U.S.-based systems,” the company said in a letter to victims of the attack. “We launched our investigation in partnership with third-party cybersecurity specialists to determine the nature and scope of the incident and activated our remediation and recovery efforts.”
After the investigation wrapped up, Chiesi determined an unauthorized third party accessed certain information maintained on its U.S.-based systems. Additionally, the company said this access was the result of an IT security issue that impacted part of its internal IT infrastructure.

read more

Skin Care Product Maker, Episciences, Suffers Cyberattack

April 27, 2025

Boise, Idaho-based skin care products maker, Episciences, Inc., suffered a cyberattack in April where victims’ personally identifiable information ended up stolen.
“On April 29, 2025, Episciences learned of suspicious activity on certain systems within its network,” the company said in a letter to victims. “Episciences immediately launched an investigation to determine the nature and scope of the activity. The investigation determined that the unauthorized actor gained access to certain files within the Episciences network between April 27, 2025, and April 29, 2025, and may have copied those files.”
Following an investigation, Episciences undertook a detailed review of all the files potentially impacted to determine what information was present in these files and to whom it related.

read more

Cyberattack Hits Curium Pharma

October 15, 2024

St. Louis, Missouri-based Curium Pharma suffered a cyberattack last October and is now letting victims know some of their personally identifiable information fell victim to the hack.
“On October 17, 2024, IT staff for Curium Pharma identified suspicious activity within the network,” the company said in a notice to victims. Furthermore, upon discovering the incident, the company took actions to secure the network, an investigation commenced, and an outside cybersecurity firm ended up engaged assist with the investigation.
As a result of the investigation, the company found the unauthorized party was able to access some data within the systems between October 15, 2024, and October 19, 2024.

read more

Cyberattack at Pharma Product Maker, Chiesi USA

August 28, 2025

Cary, North Carolina-based Chiesi USA, Inc., a pharmaceutical manufacturing and researcher, suffered a cyberattack in August where personally identifiable information ended up stolen in the hack.
“On August 28, 2025, we learned of potential unauthorized access to our U.S.-based systems,” the company said in a letter to victims of the attack. “We launched our investigation in partnership with third-party cybersecurity specialists to determine the nature and scope of the incident and activated our remediation and recovery efforts.”
After the investigation wrapped up, Chiesi determined an unauthorized third party accessed certain information maintained on its U.S.-based systems. Additionally, the company said this access was the result of an IT security issue that impacted part of its internal IT infrastructure.

read more

Second Third-Party Attack In Year at Vitamin Maker

November 11, 2025

Palm Beach Gardens, Florida-based Garden of Life, LLC suffered a second third-party cyberattack in a year and this time – like last time – personally identifiable information ended up stolen in the hack.
“On November 11, 2025, Garden of Life became aware of an unauthorized third party claiming to have accessed certain Garden of Life systems,” the company said in a notice to victims. “We immediately responded to this report by taking potentially affected systems offline and initiating an investigation by internal and external experts.”
Through this investigation, the company found on November 14 an unauthorized third party had obtained data about current and former Garden of Life employees, contractors, and business partners.

read more

Ransomware Attack at HAL Allergy Impacts Customer Deliveries

February 19, 2024

HAL Allergy was hit by a ransomware attack on February 19, 2024. HAL Allergy engaged external cybersecurity experts to assist in restoring the affected network and investigate the issue.

On March 22 the company website states: “Following the ransomware attack on February 19, several of HAL Allergy’s IT systems have been restored. The recovered systems were gradually activated in recent weeks to enable deliveries to most of our customers. As of March 14, orders that predate the ransomware attack and were ready for shipment have now been delivered to customers in Germany and the Benelux. Orders placed after February 19 will be processed as of today, March 22, except for the so-called named patient products. As soon as the named patient deliveries can also be processed you will be informed.”

read more