Repo Token Theft Opens Pharma Research Haul

A single GitHub token can open more than source code. In this case, the alleged entry point was a repo credential, and that kind of access can lead to cloned repositories, embedded secrets, and a much larger theft than the original account suggests. FulcrumSec says it used that path to steal about 1.3TB from Novo Nordisk, including intellectual property, credentials, and clinical-trial data. Novo Nordisk said the trial data was pseudonymized, so it was not directly tied to named patients, but the material still appears useful for extortion and for exposing proprietary research. The failed $25 million demand matters less than the size of the alleged haul. Once repo secrets are exposed, the risk is no longer limited to the compromised account or the trial dataset alone.

Part of the PlainSec briefing for 2026-06-17

Sources