
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack.
Novocure is a global oncology company with more than 1,300 employees and operations in North America, Europe, the Middle East, and Asia, known for inventing and commercializing Tumor Treating Fields (TTFields), a non-invasive electromagnetic field therapy for cancer tumors.
The Company disclosed in a filing with the U.S. Securities and Exchange Commission (SEC) that it discovered the incident after unauthorized access to some of its information systems in mid-August.
According to a follow-up investigation, the attackers accessed over 1,400 U.S. patient records with ID numbers, but those records didn’t contain patient names or other identifying data. However, for fewer than 50 other patients in the western U.S, the threat actors accessed identifying information and general contact information for healthcare providers.
The data breach also exposed contact information for an undisclosed number of Novocure employees, including job titles and phone numbers.
“No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional,” Novocure added.
“The Company takes its obligation to safeguard privacy and security of its patients’ data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients.”
A Novocure spokesperson was not immediately available for comment when BleepingComputer asked earlier today how the attackers breached its network and whether the Company has been in contact with them about paying a ransom.
This incident adds to of a series of cyberattacks that have affected healthcare companies over the last month.
Last month, healthcare software company Unlimited Technology Systems disclosed that a data breach in October 2025 affected more than 3.8 million people, while healthcare IT company CareCloud said that a March data breach has impacted over 3.7 million individuals.
More recently, healthcare services provider Nutex began investigating a data breach involving information theft from company servers and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident after the ShinyHunters extortion group claimed the theft of 284 million patient data records.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
