FulcrumSec Uses AI to Turn Stolen Data Into More Targeted Ransom Demands
The group’s claimed Novo Nordisk breach shows how post-compromise AI analysis can turn a data theft into a detailed negotiation strategy.
Ransomware and data-extortion victims may face a new kind of pressure campaign: attackers using AI to sort stolen files, identify sensitive assets and build tailored arguments for higher ransom demands.
FulcrumSec, a data-extortion group active since about September 2025, has used AI to analyze data taken from victim organizations and establish what it describes as a firm negotiating position, GuidePoint Security reported. The tactic is not primarily about using AI to gain access. Instead, it treats AI-assisted review of stolen information as a core part of the extortion process.
FulcrumSec typically claims to gain access through exposed or hardcoded credentials, unpatched applications and misconfigured storage. The group says it has breached 25 organizations and stolen several terabytes of data, though those claims should not be treated as independently verified.
In June, FulcrumSec told DataBreaches.net that it had compromised Danish pharmaceutical company Novo Nordisk and stolen 1.3 terabytes across 700,717 files. The group claimed the material included intellectual property related to five undisclosed drug programs, drug and RNA-delivery programs in development, and private AI models used for medical and drug-discovery purposes.
FulcrumSec said it used a team of AI agents to analyze the alleged Novo Nordisk data. It claimed the material could save a competitor three to five years of development work and initially demanded $25 million.
The group also described Novo Nordisk’s security posture in inflammatory terms, a tactic that could be designed to raise the prospect of litigation, regulatory attention or reputational harm alongside the threat of data publication. Detailed claims about exposed intellectual property and security failures can give an extortion demand more force than a generic assertion that attackers hold stolen files.
FulcrumSec has also used AI-generated materials to support public pressure campaigns. After its claimed October 2025 compromise of technology company Avnet, the group provided vx-underground with a report that reportedly included a file listing, descriptions of the stolen material, images of files, the group’s motives and other background information. Such reports can help attackers present themselves as organized, credible and prepared to disclose specific data if negotiations fail.
For compliance officers and incident-response leaders, the practical shift is that containment alone does not end the critical phase of a breach. Once attackers have copied data, they may use automated tools to identify trade secrets, regulated data, customer records, security documentation and evidence that can be framed as operational failures. Response plans should therefore account for the likelihood that stolen data will be rapidly cataloged and converted into customized extortion claims.
That means preserving evidence of what was accessed, quickly determining which repositories contained high-value material, and preparing communications and legal teams for demands that cite particular files, programs or alleged control gaps. Organizations should also expect attackers to send polished summaries to journalists, researchers or third parties in an effort to increase negotiating leverage.
There is important uncertainty around FulcrumSec’s assertions. The claimed Novo Nordisk breach, the alleged 1.3-terabyte theft, the group’s assessment of the stolen intellectual property and its claimed use of AI agents have not been independently verified in the available account. It is also unclear whether AI materially changed the outcome of any negotiation, rather than simply helping the group package information it had already stolen.
Still, the reported tactic illustrates a compliance risk that security programs should now consider explicitly: attackers may be using AI not just to accelerate intrusions, but to transform post-breach data analysis into a more precise and costly extortion mechanism.
- Ransomware Uses AI to Amp Up Negotiationslawfaremedia.org / Mainstream / Published JUL 17, 2026 / Accessed JUL 22, 2026