HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Extortion Gang Leaks Novo Nordisk’s AI/ML Ecosystem – 1 TB of Models, Datasets and Microscopy Images Exposed

Fulcrumsec released a 1.05 TB data dump from a June breach of Novo Nordisk, exposing Hugging Face models, research datasets and microscopy images. The breach originated from secrets left in client‑side JavaScript, highlighting a misconfiguration that SOC 2 continuous‑control programs must detect and evidence.

LiveThreat™ Intelligence · 📅 August 14, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

Extortion Gang Leaks Novo Nordisk’s “AI & ML Ecosystem” – 1 TB of Proprietary Models, Datasets & Microscopy Images

What Happened – The Fulcrumsec extortion group published a second data dump from a June 2026 breach of Novo Nordisk. The leak contains roughly 1.05 TB of AI/ML assets: 30 Hugging Face models, 70 datasets, and half‑a‑terabyte of cell‑painting microscopy images, alongside drug‑discovery IP.

Why It Matters for Compliance & Audit Readiness

  • The incident stems from secrets embedded in client‑side JavaScript on two unrelated subdomains – a classic front‑end misconfiguration that bypassed existing security controls.
  • SOC 2‑aligned continuous‑control monitoring must surface such exposure gaps in real time, providing auditable evidence that front‑end assets are inventory‑tracked and protected.
  • Mapping this control gap to the Control Mapping capability (continuous evidence collection & Trust Center proof) demonstrates due diligence to auditors and regulators.

Who Is Affected – Pharmaceutical & life‑science companies, AI/ML platform providers, and any organization exposing client‑side code that references secret keys or credentials.

Recommended Actions

  • Inventory all client‑side bundles and scan for embedded secrets or credentials.
  • Integrate automated control‑mapping tools that continuously verify front‑end configurations against SOC 2 security criteria.
  • Capture and retain evidence of remediation for audit trails and Trust Center reporting.

Technical Notes – Attack vector: client‑side JavaScript secret leakage (misconfiguration). No CVE cited; exposure includes proprietary Hugging Face models, drug‑R&D datasets, and microscopy images. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/extortion-gang-leaks-novo-nordisks-ai-ml-ecosystem-a-32553

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →