Novo Nordisk detects unauthorised copying of information from internal systems
Novo Nordisk reported that unauthorised actors copied information from internal systems, including a limited amount of data linked to clinical trials.

News summary
Novo Nordisk reported that unauthorised actors copied information from internal systems, including a limited amount of data linked to clinical trials. Some systems were temporarily shut down during the investigation.
Classifying data allows for a better response: knowing which systems contain particularly sensitive information helps to prioritise controls, logging, and containment measures.
Source: Reuters — 27 July 2026
What happened
Novo Nordisk reported that unauthorised actors copied information from internal systems, including a limited amount of data linked to clinical trials. During the investigation, the company temporarily shut down some systems as a containment measure, as recorded by Reuters in its review of recent incidents.
The incident is part of a series of attacks against US companies in which the goal was to extract data rather than disrupt operations, a common pattern when the value of the data outweighs the damage of a stoppage.
What it teaches companies with sensitive or regulated data
When an organisation handles especially sensitive information, such as clinical trial data, not every system carries the same value to an attacker or requires the same level of protection. Knowing where each type of data resides is the first step to deciding where to strengthen controls.
Pre-emptively shutting down systems during an investigation, as Novo Nordisk did, is a decision that can only be made quickly if a prior procedure already sets out what can be disconnected without halting the whole operation.
What to review
Measures that help limit and respond to unauthorised data copying:
- Classification of systems by the sensitivity of the information they hold.
- Monitoring controls that flag anomalous volumes of data download or copying.
- A containment plan that allows isolating specific systems without paralysing all activity.
- A notification procedure for affected individuals or entities, tailored to the type of data exposed.
Frequently Asked Questions
- What kind of data was affected?
- Information from internal systems, including a limited amount related to clinical trials, as reported by the company itself.
- Why were systems shut down during the investigation?
- As a containment measure while determining the scope of the unauthorised access.
- How does this lesson apply to a smaller company?
- By classifying which of its own information is most sensitive and deciding in advance which systems can be isolated without halting all activity.
Technology only adds value when it is properly designed, protected, and maintained. Seintec can help you implement these best practices in your company; speak to our team to assess your environment.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.