Cybersecurity entity

FulcrumSec

organization

FulcrumSec is most often covered alongside Novo Nordisk, which appears in 2 of these 3 stories. Coverage clusters in threat-intel, which accounts for 2 of those 3, with the remainder spread across 1 other category. Source depth averages 2.3 original sources per story, versus 4 across the same-window beat baseline.

Last mentioned: Jun 28, 2026

Entity pulse

Recent coverage · FulcrumSec

3 stories
8.3 avg impact
0% positive
100% negative

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.

  • 100% negative

Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.

What the coverage shows about FulcrumSec

FulcrumSec is most often covered alongside Novo Nordisk, which appears in 2 of these 3 stories. Coverage clusters in threat-intel, which accounts for 2 of those 3, with the remainder spread across 1 other category. Source depth averages 2.3 original sources per story, versus 4 across the same-window beat baseline. Their average consequence score of 8.3 runs above the beat's 7 for that window. Across a 12-day span, the pace is roughly 1.8 stories per week. This profile follows 3 Cybersecurity stories mentioning FulcrumSec across the period from June 17, 2026 to June 28, 2026.

Stories tracked
3
Per week
1.8
Sources per story
2.3

Computed from the 3 stories linked to this entity, with beat comparisons drawn from all 55 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.

Coverage cohort

Appears alongside

Other entities that clear the same relevance threshold in stories also covering FulcrumSec. Shared-story counts are live from our verified record — not editorial picks.

Timeline

  1. FulcrumSec Goes Public

    FulcrumSec posts a lengthy message on its website detailing the breach, the $25 million extortion demand, and the decision to explore private data sales after payment refusal.

  2. ShinyHunters announces additional victims

    On June 16, the group reveals new targets including Glendale Community College, Moody Bible Institute, Illinois Central College, and Houston City College.

  3. Company Discloses Breach

    Novo Nordisk publicly announces a cybersecurity incident involving unauthorized access to a limited number of internal IT systems and some personal data.

  4. Public incident disclosure

    Novo Nordisk announces a cybersecurity incident involving unauthorized access to a limited number of internal IT systems and access to certain personal data.

  5. Novo Nordisk Responds

    Roughly 48 hours after initial outreach, Novo Nordisk uses a Proton Mail address to verify the legitimacy of the claim by requesting specific file contents.

  6. Initial Extortion Contact

    FulcrumSec contacts unnamed Novo Nordisk executives demanding $25 million; the exact method is not publicly detailed.

  7. FulcrumSec ransomware attack on Global Schools Foundation

    The group exfiltrates data and disrupts operations across GSF's international network of schools in early June, causing widespread service outages.

  8. Extortion demand sent

    The group contacts unnamed Novo Nordisk executives and demands $25 million, initiating the extortion phase.

  9. Suspected initial intrusion

    FulcrumSec likely gains initial access to Novo Nordisk's networks, beginning a period of over two months of undetected data exfiltration.

  10. ShinyHunters breaches Infinite Campus via Salesforce

    Cybercriminals exploit a vulnerability to steal personal information from 137,000 school staff accounts, affecting the widely used K-12 student information system.

  11. FulcrumSec Emerges

    The cyber extortion group FulcrumSec first appears, later becoming known for credible claims and sophisticated intrusions.

Stories mentioning FulcrumSec 3

Data Breaches Negative

ShinyHunters & FulcrumSec Ramp Up EdTech Attacks: 137K Accounts Stolen

Two major threat actor groups are driving a crisis in education technology, with ShinyHunters stealing 137,000 staff records via Infinite Campus and FulcrumSec paralyzing Global Schools Foundation. The incidents reveal a shift in cybercriminal focus toward low-defence, high-value academic data repositories.

2 sources
Threat Intelligence Strongly negative

FulcrumSec Spent 2 Months Inside Novo Nordisk Networks Before $25M Demand

Cybersecurity experts assess FulcrumSec as a serious threat actor, and its two-month dwell time inside Novo Nordisk before making a $25 million extortion demand reflects advanced persistent threat tactics. The breach highlights growing risks to critical infrastructure and the evolution of cyber extortion with a harm-reduction narrative.

2 sources

FulcrumSec is linked from 3 stories on this site, each scored at or above our 35% relevance threshold — see how these pages are built.

See something wrong on this page — a misattributed entity, a wrong stat, a broken source link? Report a data issue.