HomeMalware & ThreatsExtortion Gang Exposes Novo Nordisk's AI and ML Ecosystem

Extortion Gang Exposes Novo Nordisk’s AI and ML Ecosystem

Published on

spot_img

Artificial Intelligence & Machine Learning,
Data Privacy,
Data Security

Fulcrumsec Claims 2nd Data Dump Exposes Firm’s Hugging Face Models, Drug R&D Data

Extortion Gang Exposes Novo Nordisk’s AI and ML Ecosystem
Extortion gang Fulcrumsec claims it’s now leaked “the complete enterprise Hugging Face AI and ML ecosystem” it allegedly stole in a data theft attack on drug maker Novo Nordisk. (Image: Fulcrumsec)

In a recent alarming development, the extortion group Fulcrumsec has publicly disclosed a substantial cache of confidential data, which they assert was stolen from the Danish pharmaceutical giant, Novo Nordisk. This incident represents what has been described as the second significant data dump by the group following an infiltration that allegedly occurred in June of this year. According to Fulcrumsec, the latest breach includes the entirety of Novo Nordisk’s “complete enterprise Hugging Face artificial intelligence and machine learning ecosystem.”

On Wednesday, Fulcrumsec announced via their dark web platform that they were unveiling a new trove of sensitive information not covered in their earlier release. Termed “Stage 2,” this data dump reportedly encompasses 30 Hugging Face AI models, 70 datasets, and an extensive collection of proprietary cell imaging data, amounting to half a terabyte. The total data size purportedly released by Fulcrumsec is approximately 1.05 terabytes, which they have made accessible through torrent links, with further distribution methods planned for the future.

Fulcrumsec has claimed to have received significant interest from buyers in China for the stolen data. However, they ultimately decided that “open sourcing” this data would serve a greater purpose than allowing it to be exploited by a lab in Suzhou that could potentially bypass years of research and development for mere financial gain.

The group emphasized that their first data release had already unveiled Novo Nordisk’s proprietary compounds, manufacturing recipes, and source code. Conversely, the newly leaked data, they claimed, comprises technologies and datasets that are essential for creating new pharmaceutical products.

In the same announcement, Fulcrumsec offered specific details about the nature of the leaked information, which includes confidential research related to critical health issues like obesity, diabetes, fertility, liver diseases, and several potential treatment options. The gang explained how they gained access to Novo Nordisk’s systems through security flaws found in client-side JavaScript across two unrelated subdomains of the company, showcasing a significant oversight in cybersecurity practices by a company valued at approximately $400 billion.

Fulcrumsec criticized Novo Nordisk for what they deemed a failure to adequately monitor their cybersecurity measures, stating that the company could not detect unknown IP accesses to their cloud services for an extended period. This apparent lapse in security underscores the challenges faced by large organizations in safeguarding their critical assets from sophisticated cybercriminals.

While Novo Nordisk has not yet issued a formal statement addressing these claims, the company previously acknowledged on June 11 that it had indeed suffered a breach, confirming unauthorized access to some internal IT systems. Additionally, it has been reported that another hacker group, TheUSERS007, also claimed to have compromised Novo Nordisk, allegedly stealing valuable intellectual property, including AI models associated with their popular diabetes treatments, Ozempic and Wegovy.

This recent spate of cyberattacks highlights the rising threats faced by life sciences and biotechnology firms, raising concerns about competitive advantage, product counterfeiting, and patient privacy risks. Legal experts note that organizations whose intellectual property is stolen can pursue legal actions such as injunctions and civil remedies, but they may still struggle to protect themselves from increasingly adept attackers.

Attorney Lee Kim, an expert in cybersecurity, emphasized the imperative for organizations to maintain rigorous security measures to safeguard their intellectual property and AI models. She advocates for continuous monitoring of both insider threats and external attacks, recommending that organizations adopt a multifaceted approach to protect their data.

Amid ongoing investigations into the extent of the data breach, Novo Nordisk is also contending with multiple proposed class-action lawsuits stemming from these security incidents, which further complicates the legal ramifications of this troubling event.

Source link

Latest articles

Twitch Default Enables Opt-Out for AI Training

Twitch Implements New Privacy Control for Streamers Amid Concerns Over AI Training Twitch, the popular...

Researchers Connect Suspected Chinese APT to Hack-for-Hire Activities

Dual Threat: Jewelbug's Cyber Espionage and Cryptocurrency Fraud Operations Security researchers from Broadcom’s Threat Hunter...

White House Approves Offensive Cyber Operations Targeting Foreign Syndicates

White House Takes Bold Action Against Foreign Cybercrime On August 12, 2026, President Donald J....

Def Con Dolt Suspected in Delta Wi-Fi Hack

In a recent roundup of cybersecurity incidents, significant events have captured attention, including a...

More like this

Twitch Default Enables Opt-Out for AI Training

Twitch Implements New Privacy Control for Streamers Amid Concerns Over AI Training Twitch, the popular...

Researchers Connect Suspected Chinese APT to Hack-for-Hire Activities

Dual Threat: Jewelbug's Cyber Espionage and Cryptocurrency Fraud Operations Security researchers from Broadcom’s Threat Hunter...

White House Approves Offensive Cyber Operations Targeting Foreign Syndicates

White House Takes Bold Action Against Foreign Cybercrime On August 12, 2026, President Donald J....