HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Novo Nordisk Breach Exposes Over 1 TB of Sensitive Data via Stolen GitHub Access Tokens

FulcrumSec used hard‑coded GitHub and Azure DevOps tokens found in client‑side JavaScript to infiltrate Novo Nordisk’s cloud environment, exfiltrating more than 1 TB of drug research and patient data. The breach underscores the need for continuous credential‑management controls and audit‑ready evidence of secret‑handling policies.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
databreachtoday.com

Novo Nordisk Breach Exposes Over 1 TB of Sensitive Data via Stolen GitHub Access Tokens

What Happened — Attackers from the FulcrumSec extortion group leveraged hard‑coded GitHub personal access tokens (PATs) and an Azure DevOps token that were unintentionally embedded in client‑side JavaScript on two public Novo Nordisk sub‑domains. The stolen tokens granted unfettered access to more than a thousand private repositories, which contained additional cloud‑service credentials. Over a two‑month period the actors moved laterally through AWS and Hugging Face environments and exfiltrated roughly 1 TB of experimental drug data, patient records, and other proprietary information.

Why It Matters for Trust & Control Assurance

  • This incident illustrates a classic failure of credential hygiene—a control objective that continuous‑control‑assurance programs must monitor, evidence, and remediate.
  • Demonstrable secret‑management policies and automated scanning of code repositories are essential evidence for audit readiness under the Identify/Protect functions of NIST CSF 2.0.
  • A robust access‑control assurance capability (e.g., Verisq’s Access Controls module) provides the continuous monitoring and proof points needed to show that privileged tokens are inventoried, rotated, and protected.

Who Is Affected – Pharmaceutical & life‑science companies, cloud‑native development teams, and any organization exposing secrets in client‑side code.

Recommended Actions

  • Inventory all GitHub and Azure DevOps personal access tokens; enforce least‑privilege scopes and expiration policies.
  • Deploy automated secret‑scanning tools in CI/CD pipelines to detect hard‑coded credentials before code reaches production.
  • Update governance policies to require regular credential rotation and enforce “no secrets in client‑side code” rules.
  • Capture evidence of these controls in a continuous‑monitoring platform to support audit readiness.

Technical Notes – Attack vector: stolen credentials (GitHub PAT, Azure DevOps token) embedded in JavaScript bundles; lateral movement via AWS and Hugging Face instances; data exfiltrated over two months. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/novo-nordisk-data-breach-tied-to-stolen-github-access-tokens-a-32802

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →