In your conversation with DataBreaches, you mentioned a homegrown AI tool called Venomware. Can you explain in more detail how it actually works?
Venomware is not a tool. It's a mirror. We built it to reflect the reality of modern security: most companies are spending billions to secure doors that were never meant to be locked. It doesn't exploit. It observes. It finds the gap. It walks through. By the time you realize what happened, we're already gone. Not because we're fast, but because you're slow.
You said the entire operation against Novo Nordisk took less than one hour. Was any part of it done manually, or was it fully autonomous after you launched Venomware?
The operation was hybrid. Venomware handled everything it could. Humans made the final decisions. But the truth is, we could have automated the whole thing. We chose not to because we wanted to see how long it would take them to notice. They didn't. That's not a flex. That's an indictment.
How long have you been developing Venomware? Was this the first real-world deployment, or had you tested it on other targets before?
We've been building it for three years. Novo wasn't the first. They were just the first to be arrogant enough to ignore us. The others paid. They understood the situation. They knew what we had. Novo? They were still asking about deletion processes while their crown jewels were sitting on our servers. That's not a negotiation. That's a delay tactic disguised as incompetence.
You exfiltrated 16.7 GB of trained model weights and focused heavily on AI assets. Why did you choose to target the AI models specifically? What makes them more valuable to you than manufacturing data or clinical records?
We went after the AI models because they're irreplaceable. Everything else, including manufacturing data and clinical records, can be recreated. But AI models represent years of research, billions in investment, and the competitive future of an organization. When you take that, you're not just taking data. You're taking leverage.
You deliberately avoided OT/SCADA systems and bulk clinical or personally identifiable information. Was that a conscious decision from the beginning? What was the reasoning behind it?
We avoided OT and PII intentionally. We could have taken them. We chose not to. Not because we couldn't, but because we have more class than they have security. That's not a virtue. That's a standard. We don't target infrastructure that could harm patients. We don't target data that could ruin lives. That's the line we draw. They should have drawn it too. Instead, they left everything exposed and hoped no one would look.
You demanded $50 million, significantly more than FulcrumSec's $25 million demand. Considering that the data you took consists mostly of AI and intellectual property rather than medical PII, what factors did you use to calculate that amount?
The $50 million figure wasn't random. It was calculated based on the value of their data to competitors, the cost of replacing their AI pipeline, and the potential damage to their future revenue. Fifty million dollars is a rounding error compared to what they'll lose. They just don't realize it yet. They will.
In previous operations, you resolved everything privately without any public disclosure. Why did you decide to go public so quickly this time with Novo Nordisk?
We went public because they forced us to. We gave them every opportunity to resolve this quietly: verification, a deletion process, and a path to closure. They used our time to prepare a press release instead of making a payment. They thought silence would make us go away. It didn't. It made us speak. And now the world is listening.
You described Venomware as a "digital predator" that "walks in" rather than breaks in. Does that mean there were no exploits, no social engineering, and no vulnerabilities used in this operation at all?
No exploits. No social engineering. We didn't break in. We walked in. We used legitimate API calls, valid tokens, and exposed endpoints. There were no zero-days. No sophisticated exploits. Just a series of basic assumptions that should have been questioned. That's the most embarrassing part for them: not that we were good, but that they were that bad.
Your group has five core members and 12 affiliates operating across different time zones. How do you coordinate such a distributed team during an operation like this? Who makes the final decisions regarding targets and ransom amounts?
We're decentralized by design. No single leader. No single point of failure. No single point of ego. Every operator has autonomy within agreed parameters. The Boss sets the standard: precision, silence, and integrity. That's not a title. That's a commitment.
Novo Nordisk was apparently not even on your radar until early June. What made you choose the company specifically?
Novo was chosen for one reason: vulnerability. We scanned the pharmaceutical sector. Novo had visible infrastructure gaps. They were the easiest target we've ever seen. We didn't choose them because of their reputation. We chose them because they were exposed. Their name came later. Their arrogance sealed their fate.
What advice would you give companies that want to avoid becoming your next target?
My advice to companies? Stop treating security like a checkbox. Audit exposed services. Rotate credentials. Monitor API usage. Assume you've already been breached. And if someone offers to show you your vulnerabilities, listen. Because the next one won't ask. The next one won't warn. The next one will just take.