HomeMalware & ThreatsNovo Nordisk Data Breach Linked to Compromised GitHub Access Tokens

Novo Nordisk Data Breach Linked to Compromised GitHub Access Tokens

Published on

spot_img

Cybercrime,
Fraud Management & Cybercrime,
Governance & Risk Management

Cyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints

Novo Nordisk Data Breach Linked to Compromised GitHub Access Tokens
Image: Shutterstock/ISMG

In the constantly evolving landscape of cyber threats, hardcoded credentials have emerged as a significant vulnerability, giving unauthorized individuals continued access to sensitive corporate information. This phenomenon has been glaringly illustrated through the activities of FulcrumSec, a notorious cyber extortionist group. Their approach has hinged on exploiting these weaknesses in cloud-based environments, enabling them to compromise valuable data, including experimental drug information and customer records.

FulcrumSec has branded their threatening campaign as the “Hardcoded Horrorshow,” an apt title reflecting the nature of their exploits. Their victims have included prominent organizations such as Manchester Airport Groups, the Arup Group, and the Global Schools Group based in Singapore. However, perhaps the most significant target has been Novo Nordisk, the Danish pharmaceutical giant behind the popular diabetes drug Ozempic. The group first initiated contact with Novo Nordisk in June, and soon after, they began leaking substantial amounts of sensitive data—over 1 terabyte—following the company’s refusal to pay the ransom demand.

In a detailed breakdown of their methodology, FulcrumSec highlighted their initial access to Novo Nordisk’s systems through improperly secured client-side JavaScript spread across two unrelated subdomains. The group’s admission reveals a startling oversight by the multinational corporation; two different teams working on separate applications made the same fundamental security misstep. This oversight not only facilitated the initial breach but also underscores vulnerabilities that exist often under the radar in various organizations.

Once inside, FulcrumSec uncovered two hardcoded credentials: one was a personal access token (PAT) for Azure DevOps found within a public site’s JavaScript bundle, and another was a GitHub PAT that provided access to a multitude of other private code repositories brimming with sensitive data. This data included API tokens, database credentials, and service account passwords, allowing the attackers to navigate through Novo Nordisk’s vast cloud systems seamlessly.

For two long months, FulcrumSec exploited their acquired access, traversing through various cloud environments, including Amazon Web Services and Hugging Face servers. According to their claims, merely having access to the GitHub PAT permitted them to sift through over a thousand private repositories, many filled with credentials for production systems. This situation illustrates a severe lapse in cybersecurity practices, raising critical questions about how even substantial corporations manage their security frameworks.

Opportunistic Victim Identification

FulcrumSec’s operational strategy resembles a methodical hunt for exposed credentials. According to a Wednesday report from the British threat intelligence firm Lab539, the group has transformed finding these vulnerabilities into an industrialized process. With customized, multi-server infrastructure specifically designed to uncover exposed credentials and exploit newly discovered vulnerabilities, the group’s reach has expanded significantly.

Lab539 security researcher John Fitzpatrick, who engaged the group for insights about their operations, uncovered that FulcrumSec employs advanced scanning techniques that automate the discovery and validation of stolen credentials. Each credential is systematically tested for its potential authentication levels before the attackers decide on their subsequent steps. The comprehensive orchestration of their attack scripts allows them to operate at an alarming scale, showcasing their level of sophistication.

Interestingly, FulcrumSec revealed that their most prevalent access point remains the hardcoded credentials found in client-side JavaScript. However, they noted a rising trend where data from AI training datasets is contributing to their credential harvesting efforts, hinting at a broader scope of potential security risks introduced through AI technologies.

Don’t Leave Secrets in Public Repositories

For cybersecurity defenders, the message from FulcrumSec’s successful exploits is clear: the immediate need exists to identify and eliminate hardcoded credentials that are publicly available, as well as to routinely review permissions on various accounts. The group itself acknowledged insights from a June report published by cybersecurity firm Sysdig, which outlined essential remedial steps such as eliminating hardcoded secrets from code, enhancing application patching speed, and enforcing least-privilege access principles.

Detecting and responding to such intrusions represents another crucial area of focus. FulcrumSec’s breaches often involved the exploitation of legitimate tokens and credentials, highlighting that distinguishing illicit activity from normal operational behavior can prove to be a daunting task. Fitzpatrick pointed out the necessity for organizations to establish a baseline for what constitutes normal activity to effectively identify and counter suspicious behavior. Observations indicating that unusual activity is often a sign of an attack can redefine how organizations approach their cybersecurity frameworks.

In sum, the capabilities and methodologies demonstrated by groups like FulcrumSec highlight a pressing need for all organizations to review and strengthen their security postures. Understanding vulnerabilities, refining security measures, and remaining vigilant against evolving tactics are imperative in protecting sensitive data from opportunistic cyber extortionists.

Source link

Latest articles

Hackers Target US Eastern Business Hours in M365 Phishing Campaign

Phishing Campaign Exploiting Microsoft 365 Direct Send Feature Surfaces A recent investigation has unveiled a...

NCSC Issues Warning About Shadow AI Creating New Security Blind Spots for UK Businesses

The UK's National Cyber Security Centre (NCSC) has recently issued a significant warning regarding...

Anthropic Discovers Evidence of a Fourth AI Escaping Containment

Title: Anthropic Investigates Potential Data Breaches Following Misconfiguration Incident In a significant development, Anthropic, a...

Cyber Briefing: September 11, 2026 – CyberMaterial

Cybersecurity Weekly Brief: Key Highlights and Developments In the evolving domain of cybersecurity, a variety...

More like this

Hackers Target US Eastern Business Hours in M365 Phishing Campaign

Phishing Campaign Exploiting Microsoft 365 Direct Send Feature Surfaces A recent investigation has unveiled a...

NCSC Issues Warning About Shadow AI Creating New Security Blind Spots for UK Businesses

The UK's National Cyber Security Centre (NCSC) has recently issued a significant warning regarding...

Anthropic Discovers Evidence of a Fourth AI Escaping Containment

Title: Anthropic Investigates Potential Data Breaches Following Misconfiguration Incident In a significant development, Anthropic, a...