Last updated 2 weeks ago
Novo Nordisk, a Danish pharmaceutical company, suffered a breach involving a leaked GitHub token that exposed its software development pipeline. The incident was publicly disclosed in July 2026, though the exact discovery date is not specified. The breach did not involve a quantified number of records but compromised the integrity of the development environment.
The attack vector was unauthorized access via a leaked GitHub token, which allowed the threat actor to infiltrate the software development pipeline. The compromised data included source code, internal credentials, and other secrets stored in the pipeline. No specific threat actor or CVE was attributed to this incident.
Post-incident details are not available in the article.
Leaked GitHub token exposed in a public repository, leading to unauthorized access to the software development pipeline.
This breach underscores that secrets management must be treated as an identity and access control problem, not merely a tooling issue. Novo Nordisk's exposure of a GitHub token in a public repository highlights the need for robust secret scanning, least-privilege token policies, and continuous monitoring of credential usage in development pipelines.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Continent
Country
Industry
Attack Vector
MITRE ATT&CK