Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Novo Nordisk IT Security Incident Exposes Limited Patient and HCP Data Samiksha Jain
    The Novo Nordisk IT Security Incident has resulted in unauthorized access to a limited number of the pharmaceutical company's internal IT systems, leading to the exposure of certain non-public information, including personal data related to clinical trial participants and healthcare professionals. The Denmark-based healthcare company confirmed that an investigation is underway with support from external cybersecurity experts and relevant authorities. According to Novo Nordisk, certain data wa
     

Novo Nordisk IT Security Incident Exposes Limited Patient and HCP Data

Novo Nordisk IT Security Incident

The Novo Nordisk IT Security Incident has resulted in unauthorized access to a limited number of the pharmaceutical company's internal IT systems, leading to the exposure of certain non-public information, including personal data related to clinical trial participants and healthcare professionals. The Denmark-based healthcare company confirmed that an investigation is underway with support from external cybersecurity experts and relevant authorities. According to Novo Nordisk, certain data was copied externally without authorization during the incident. In response, the company temporarily took some internal systems offline and is gradually restoring affected environments in a controlled manner. The company stated that its core business operations remain unaffected.

Novo Nordisk IT Security Incident Under Investigation

Novo Nordisk disclosed that it identified unauthorized access to a limited number of internal IT systems and immediately launched an investigation into the matter. The company said multiple security measures were implemented following the discovery, including taking selected systems offline to protect its environment. While recovery efforts continue, Novo Nordisk emphasized that business operations remain operational and that the delivery of products and support to patients has not been disrupted. "As part of our response, multiple security measures have been taken, including temporarily taking certain internal IT systems offline to protect our environment. We are working to bring the affected systems back online in a controlled and safe manner; however, we acknowledge this process takes time," reads the official statement. Novo Nordisk IT Security Incident Exposes Limited Patient and HCP Data The healthcare company also confirmed that non-public data, including personal information, was copied externally without authorization. Impacted parties are being notified as appropriate.

Patient Data Included Clinical Trial Information

Information provided by Novo Nordisk to affected patients shows that the exposed data involved a limited amount of information related to participants in certain clinical trials. The affected categories of personal data may include:
  • Patient ID and information on trial participation
  • Sex
  • Year of birth
  • Biomarkers
  • Health and immunogenicity data
  • Lifestyle factors, including smoking, alcohol use, and BMI
The company stated that the exposed information was pseudonymized and not directly linked to patient names or other direct identifiers. According to Novo Nordisk, identifying individual patients would require access to additional information that was not exposed during the incident. As a result, the company said it does not believe the incident presents any immediate risk to affected patients. However, patients have been advised to remain vigilant and report any unusual activity that may be connected to the breach.

Healthcare Professional Data Also Affected

Novo Nordisk also issued separate notifications to affected healthcare professionals, confirming that a limited amount of Healthcare Professional (HCP) Data had been copied as part of the incident. The categories of affected information include:
  • Name and registration number
  • Email address
  • Phone number
  • WhatsApp details
  • Office location
The company warned that the exposure of this information could increase the risk of Phishing Attacks, fraudulent communications, and impersonation attempts targeting healthcare professionals through email, phone calls, or messaging applications. Affected individuals have been advised to remain cautious when responding to unexpected communications and to report suspicious activity.

Response and Recovery Efforts Continue

Following the discovery of the Data Breach, Novo Nordisk engaged cybersecurity experts to assist with investigation and remediation efforts. The company said it has implemented additional security measures and is working to restore affected systems safely. While acknowledging that the recovery process may take time, Novo Nordisk reiterated that protecting the security and integrity of systems used by employees, customers, patients, and stakeholders remains a top priority. The organization stated that there is no need for affected patients or healthcare professionals to take any specific action as a direct result of the incident beyond remaining alert to unusual communications. Novo Nordisk, founded in 1923 and headquartered in Denmark, employs approximately 67,900 people across 80 countries and markets its products in around 170 countries worldwide. The Cyber Express Team has reached out to Novo Nordisk for additional information regarding the incident, including the scope of affected records and the nature of the unauthorized access. However, the company had not responded at the time of publication.
  • ✇Firewall Daily – The Cyber Express
  • INTERPOL Busts Massive Cybercrime Network Across MENA, 201 Arrested Samiksha Jain
    A large-scale cybercrime crackdown led by INTERPOL has resulted in 201 arrests and the identification of 3,867 victims across the Middle East and North Africa region. The coordinated operation, known as Operation Ramz, is being described as the first cybercrime operation of its scale conducted by INTERPOL in the MENA region. The operation ran between October 2025 and February 28, 2026, bringing together law enforcement agencies from 13 countries to disrupt malicious cyber infrastructure linke
     

INTERPOL Busts Massive Cybercrime Network Across MENA, 201 Arrested

Operation Ramz

A large-scale cybercrime crackdown led by INTERPOL has resulted in 201 arrests and the identification of 3,867 victims across the Middle East and North Africa region. The coordinated operation, known as Operation Ramz, is being described as the first cybercrime operation of its scale conducted by INTERPOL in the MENA region. The operation ran between October 2025 and February 28, 2026, bringing together law enforcement agencies from 13 countries to disrupt malicious cyber infrastructure linked to phishing, malware campaigns, and online scams. Authorities also identified 382 additional suspects and seized 53 servers during the operation. Operation Ramz focused on tackling cyber threats that continue to cause financial and operational damage across the region. Participating countries included Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the UAE. According to INTERPOL, nearly 8,000 intelligence packages and data points were shared among participating countries to support investigations and help authorities trace malicious infrastructure connected to cybercriminal activity. INTERPOL said the operation highlighted the growing importance of cross-border collaboration in combating cybercrime networks that often operate across multiple jurisdictions. “In a world where cybercriminals exploit the digital landscape without borders, Operation Ramz demonstrates the effectiveness of global collaboration,” said Neal Jetton. He added that INTERPOL remains committed to working with member countries and private-sector partners to dismantle malicious infrastructure and bring cybercriminals to justice.

Cybercrime Investigations Across MENA

Authorities involved in Operation Ramz uncovered several cybercrime operations tied to phishing schemes, malware distribution, and financial fraud. In Qatar, investigators used intelligence gathered during the operation to identify compromised devices that were unknowingly being used to spread malicious threats. Officials secured the infected systems and notified affected users to prevent further misuse. Jordanian authorities uncovered a fraudulent investment scam operating through what appeared to be a legitimate online trading platform. Victims were convinced to deposit funds before the platform disappeared. During a raid, police found 15 individuals carrying out the scams. However, investigators later determined the workers themselves were victims of human trafficking who had been lured from Asian countries with fake job offers. Their passports were confiscated upon arrival, and they were forced into cyber fraud operations. Two individuals suspected of organizing the scheme were arrested. In Oman, investigators identified a server hosted in a private residence containing sensitive information. Although the owner had legitimate access to the data, authorities found the server had multiple critical vulnerabilities and malware infections. Officials disabled the server to reduce further cybersecurity risks. Authorities in Algeria dismantled a phishing-as-a-service website during the operation. Law enforcement seized servers, computers, mobile devices, and hard drives containing phishing scripts and malicious software. One suspect was arrested in connection with the activity. Meanwhile, Moroccan authorities seized computers, smartphones, and external hard drives containing banking data and phishing software. Three individuals are currently facing judicial proceedings while investigations continue into other possible suspects.

Private Sector Partners Supported Operation Ramz

Several cybersecurity and threat intelligence organizations, including Team Cymru, Kaspersky, Group-IB, the Shadowserver Foundation, and TrendAI, supported operation Ramz. These organizations worked with INTERPOL to provide threat intelligence, internet visibility, and technical support to identify malicious servers and track illegal cyber activity linked to phishing, malware, and online scam networks. Joe Sander said cybercrime requires a coordinated international response involving both law enforcement and private-sector intelligence partners. “Cybercrime is borderless, and the only effective response is one that is equally borderless,” Sander said. “Operation Ramz is exactly that kind of response.” Team Cymru stated that it contributed external threat intelligence and internet-scale telemetry to help authorities map cybercriminal infrastructure and generate operational leads during the investigations.

Rising Focus on MENA Cybercrime Threats

The success of Operation Ramz reflects the growing focus on cybersecurity cooperation in the MENA region as phishing attacks, malware campaigns, and financial cyber scams continue to evolve. The operation also demonstrated how intelligence sharing between governments and cybersecurity firms can help authorities rapidly identify malicious infrastructure and prevent additional victims. Operation Ramz received support from Qatar’s Ministry of Interior and partial funding from the European Union and the Council of Europe under the CyberSouth+ project.
❌
❌