# FulcrumSec

Type: organization

Source: GetYourBrief — https://getyourbrief.com/entity/fulcrumsec
Canonical HTML page: https://getyourbrief.com/entity/fulcrumsec

## Timeline

- **2026-06-16**: FulcrumSec Goes Public — FulcrumSec posts a lengthy message on its website detailing the breach, the $25 million extortion demand, and the decision to explore private data sales after payment refusal.
- **2026-06-16**: ShinyHunters announces additional victims — On June 16, the group reveals new targets including Glendale Community College, Moody Bible Institute, Illinois Central College, and Houston City College.
- **2026-06-16**: FulcrumSec posts public claim — The group publishes a detailed message on its website describing the hack and threatens private data sales or open-source release after non-payment.
- **2026-06-11**: Company Discloses Breach — Novo Nordisk publicly announces a cybersecurity incident involving unauthorized access to a limited number of internal IT systems and some personal data.
- **2026-06-11**: Public incident disclosure — Novo Nordisk announces a cybersecurity incident involving unauthorized access to a limited number of internal IT systems and access to certain personal data.
- **2026-06-03**: Novo Nordisk Responds — Roughly 48 hours after initial outreach, Novo Nordisk uses a Proton Mail address to verify the legitimacy of the claim by requesting specific file contents.
- **2026-06-03**: Novo Nordisk engages — Novo Nordisk uses a random Proton Mail address to contact FulcrumSec and requests specific files for verification, confirming awareness of the breach.
- **2026-06-01**: Initial Extortion Contact — FulcrumSec contacts unnamed Novo Nordisk executives demanding $25 million; the exact method is not publicly detailed.
- **2026-06**: FulcrumSec ransomware attack on Global Schools Foundation — The group exfiltrates data and disrupts operations across GSF's international network of schools in early June, causing widespread service outages.
- **2026-06-01**: Extortion demand sent — The group contacts unnamed Novo Nordisk executives and demands $25 million, initiating the extortion phase.
- **2026-04-01**: Suspected initial intrusion — FulcrumSec likely gains initial access to Novo Nordisk's networks, beginning a period of over two months of undetected data exfiltration.
- **2026-03**: ShinyHunters breaches Infinite Campus via Salesforce — Cybercriminals exploit a vulnerability to steal personal information from 137,000 school staff accounts, affecting the widely used K-12 student information system.
- **2025-10**: FulcrumSec Emerges — The cyber extortion group FulcrumSec first appears, later becoming known for credible claims and sophisticated intrusions.

## Recent coverage (9 stories, network-wide)

### 1TB of Patient Data Exposed in Novo Nordisk Hack, $25M Extortion Attempt
2026-06-28 17:22:44 · Sector: health · Sentiment: Strongly negative · Impact: 8/10 · Sources: 3

A cyberattack on Novo Nordisk has potentially exposed over a terabyte of sensitive health information, including patient, doctor, and clinical trial data, after a $25 million extortion demand was refused. The incident highlights critical vulnerabilities in protecting personal health data within the pharmaceutical industry.
Full story: https://gethealthbrief.com/story/novo-nordisk-patient-data-breach-25m

### FulcrumSec's 2-Month Intrusion at Novo Nordisk Yields 1TB Data, $25M Ransom
2026-06-28 17:22:38 · Sector: cyber · Sentiment: Strongly negative · Impact: 8/10 · Sources: 3

Cyber extortion group FulcrumSec executed a sophisticated, two-month-long network intrusion at Novo Nordisk, exfiltrating 1TB of sensitive data and demanding $25 million. The group's tactics and the refusal to pay offer a detailed case study for threat intelligence and incident response teams.
Full story: https://getcyberbrief.com/story/fulcrumsec-novo-nordisk-2-month-breach

### Novo Nordisk Hack: 1TB of Drug IP Stolen, $25M Extortion Demand
2026-06-28 17:22:33 · Sector: bio · Sentiment: Strongly negative · Impact: 8/10 · Sources: 3

Biotech giant Novo Nordisk faces a catastrophic IP theft as hackers claim to have stolen over a terabyte of proprietary drug data, including formulas and trial results, and are now exploring private sales after a $25 million ransom was refused.
Full story: https://getbiobrief.com/story/novo-nordisk-drug-ip-theft-25m

### ShinyHunters & FulcrumSec Ramp Up EdTech Attacks: 137K Accounts Stolen
2026-06-18 00:56:16 · Sector: cyber · Sentiment: Negative · Impact: 8/10 · Sources: 2

Two major threat actor groups are driving a crisis in education technology, with ShinyHunters stealing 137,000 staff records via Infinite Campus and FulcrumSec paralyzing Global Schools Foundation. The incidents reveal a shift in cybercriminal focus toward low-defence, high-value academic data repositories.
Full story: https://getcyberbrief.com/story/cyber-edtech-breach-shinyhunters-fulcrumsec-timeline

### 137K School Staff Accounts Hacked: EdTech Data Crisis Hits 3,200 Districts
2026-06-18 00:55:05 · Sector: edtech · Sentiment: Negative · Impact: 8/10 · Sources: 2

The education technology sector is under siege after ShinyHunters breached Infinite Campus, exposing 137,000 staff accounts and potentially impacting 11 million students. New attacks on colleges and international schools signal a systemic vulnerability that demands immediate action from district leaders and vendors.
Full story: https://getedtechbrief.com/story/edtech-data-breach-137k-staff-accounts-infinite-campus

### 1 TB of Novo Nordisk Data Stolen: 11,500 Clinical Trial Patients Exposed
2026-06-17 03:12:06 · Sector: health · Sentiment: Strongly negative · Impact: 9/10 · Sources: 2

A cyber extortion group claims to have stolen over a terabyte of data from pharmaceutical giant Novo Nordisk, including clinical trial data of 11,500 patients. While some sensitive data is being withheld, the breach highlights critical vulnerabilities in healthcare data security and could trigger regulatory scrutiny under GDPR and other frameworks.
Full story: https://gethealthbrief.com/story/novo-nordisk-breach-patient-data

### FulcrumSec Spent 2 Months Inside Novo Nordisk Networks Before $25M Demand
2026-06-17 03:12:00 · Sector: cyber · Sentiment: Strongly negative · Impact: 9/10 · Sources: 2

Cybersecurity experts assess FulcrumSec as a serious threat actor, and its two-month dwell time inside Novo Nordisk before making a $25 million extortion demand reflects advanced persistent threat tactics. The breach highlights growing risks to critical infrastructure and the evolution of cyber extortion with a harm-reduction narrative.
Full story: https://getcyberbrief.com/story/fulcrumsec-novo-nordisk-breach-ttps

### $25M Extortion Bid Exposes Novo Nordisk’s Unreleased Drug Pipeline
2026-06-17 03:11:54 · Sector: bio · Sentiment: Strongly negative · Impact: 9/10 · Sources: 2

FulcrumSec's breach of Novo Nordisk could jeopardize years of R&D as stolen data includes proprietary information on released and unreleased drugs, trial data, and manufacturing processes. With the extortion failure and potential data sale, rival pharma firms may gain competitive intelligence, threatening Novo's market position.
Full story: https://getbiobrief.com/story/novo-nordisk-pipeline-breach

### Novo Nordisk’s Internal AI Models Among 1 TB Data Stolen in Cyberattack
2026-06-17 03:11:48 · Sector: ai · Sentiment: Strongly negative · Impact: 9/10 · Sources: 2

The FulcrumSec breach exposed Novo Nordisk’s internal AI model information alongside drug data, potentially compromising years of machine learning work used in drug discovery. The theft of proprietary AI assets highlights escalating cyber risks for AI-driven pharma innovation.
Full story: https://getaibrief.com/story/novo-nordisk-ai-model-breach

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getyourbrief.com/guides/methodology for the full editorial methodology.