# FulcrumSec

Type: organization

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/fulcrumsec
Canonical HTML page: https://getcyberbrief.com/entity/fulcrumsec

## Timeline

- **2026-06-16**: FulcrumSec Goes Public — FulcrumSec posts a lengthy message on its website detailing the breach, the $25 million extortion demand, and the decision to explore private data sales after payment refusal.
- **2026-06-16**: ShinyHunters announces additional victims — On June 16, the group reveals new targets including Glendale Community College, Moody Bible Institute, Illinois Central College, and Houston City College.
- **2026-06-16**: FulcrumSec posts public claim — The group publishes a detailed message on its website describing the hack and threatens private data sales or open-source release after non-payment.
- **2026-06-11**: Company Discloses Breach — Novo Nordisk publicly announces a cybersecurity incident involving unauthorized access to a limited number of internal IT systems and some personal data.
- **2026-06-11**: Public incident disclosure — Novo Nordisk announces a cybersecurity incident involving unauthorized access to a limited number of internal IT systems and access to certain personal data.
- **2026-06-03**: Novo Nordisk Responds — Roughly 48 hours after initial outreach, Novo Nordisk uses a Proton Mail address to verify the legitimacy of the claim by requesting specific file contents.
- **2026-06-03**: Novo Nordisk engages — Novo Nordisk uses a random Proton Mail address to contact FulcrumSec and requests specific files for verification, confirming awareness of the breach.
- **2026-06-01**: Initial Extortion Contact — FulcrumSec contacts unnamed Novo Nordisk executives demanding $25 million; the exact method is not publicly detailed.
- **2026-06**: FulcrumSec ransomware attack on Global Schools Foundation — The group exfiltrates data and disrupts operations across GSF's international network of schools in early June, causing widespread service outages.
- **2026-06-01**: Extortion demand sent — The group contacts unnamed Novo Nordisk executives and demands $25 million, initiating the extortion phase.
- **2026-04-01**: Suspected initial intrusion — FulcrumSec likely gains initial access to Novo Nordisk's networks, beginning a period of over two months of undetected data exfiltration.
- **2026-03**: ShinyHunters breaches Infinite Campus via Salesforce — Cybercriminals exploit a vulnerability to steal personal information from 137,000 school staff accounts, affecting the widely used K-12 student information system.
- **2025-10**: FulcrumSec Emerges — The cyber extortion group FulcrumSec first appears, later becoming known for credible claims and sophisticated intrusions.

## Recent coverage (3 stories)

### FulcrumSec's 2-Month Intrusion at Novo Nordisk Yields 1TB Data, $25M Ransom
2026-06-28 17:22:38 · Sentiment: Strongly negative · Impact: 8/10 · Sources: 3

Cyber extortion group FulcrumSec executed a sophisticated, two-month-long network intrusion at Novo Nordisk, exfiltrating 1TB of sensitive data and demanding $25 million. The group's tactics and the refusal to pay offer a detailed case study for threat intelligence and incident response teams.
Full story: https://getcyberbrief.com/story/fulcrumsec-novo-nordisk-2-month-breach

### ShinyHunters & FulcrumSec Ramp Up EdTech Attacks: 137K Accounts Stolen
2026-06-18 00:56:16 · Sentiment: Negative · Impact: 8/10 · Sources: 2

Two major threat actor groups are driving a crisis in education technology, with ShinyHunters stealing 137,000 staff records via Infinite Campus and FulcrumSec paralyzing Global Schools Foundation. The incidents reveal a shift in cybercriminal focus toward low-defence, high-value academic data repositories.
Full story: https://getcyberbrief.com/story/cyber-edtech-breach-shinyhunters-fulcrumsec-timeline

### FulcrumSec Spent 2 Months Inside Novo Nordisk Networks Before $25M Demand
2026-06-17 03:12:00 · Sentiment: Strongly negative · Impact: 9/10 · Sources: 2

Cybersecurity experts assess FulcrumSec as a serious threat actor, and its two-month dwell time inside Novo Nordisk before making a $25 million extortion demand reflects advanced persistent threat tactics. The breach highlights growing risks to critical infrastructure and the evolution of cyber extortion with a harm-reduction narrative.
Full story: https://getcyberbrief.com/story/fulcrumsec-novo-nordisk-breach-ttps

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.