Extortion Gang Leaks Novo Nordisk’s “AI & ML Ecosystem” – 1 TB of Proprietary Models, Datasets & Microscopy Images
What Happened – The Fulcrumsec extortion group published a second data dump from a June 2026 breach of Novo Nordisk. The leak contains roughly 1.05 TB of AI/ML assets: 30 Hugging Face models, 70 datasets, and half‑a‑terabyte of cell‑painting microscopy images, alongside drug‑discovery IP.
Why It Matters for Compliance & Audit Readiness
- The incident stems from secrets embedded in client‑side JavaScript on two unrelated subdomains – a classic front‑end misconfiguration that bypassed existing security controls.
- SOC 2‑aligned continuous‑control monitoring must surface such exposure gaps in real time, providing auditable evidence that front‑end assets are inventory‑tracked and protected.
- Mapping this control gap to the Control Mapping capability (continuous evidence collection & Trust Center proof) demonstrates due diligence to auditors and regulators.
Who Is Affected – Pharmaceutical & life‑science companies, AI/ML platform providers, and any organization exposing client‑side code that references secret keys or credentials.
Recommended Actions –
- Inventory all client‑side bundles and scan for embedded secrets or credentials.
- Integrate automated control‑mapping tools that continuously verify front‑end configurations against SOC 2 security criteria.
- Capture and retain evidence of remediation for audit trails and Trust Center reporting.
Technical Notes – Attack vector: client‑side JavaScript secret leakage (misconfiguration). No CVE cited; exposure includes proprietary Hugging Face models, drug‑R&D datasets, and microscopy images. Source: DataBreachToday