
Health technology company Novocure says a cyberattack in mid-August exposed the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients.
Novocure is a global oncology company with more than 1,300 employees and offices in North America, Europe, the Middle East and Asia, known for inventing and commercializing Tumor Treating Fields (TTFields), a non-invasive electromagnetic field therapy for cancerous tumors.
the company announced in a filing with the US Securities and Exchange Commission (SEC) that the incident was discovered following unauthorized access to some of its information systems in mid-August.
According to a follow-up investigation, the attackers accessed over 1,400 U.S. patient records with ID numbers, but these did not contain patient names or other identifying data. However, threat actors accessed identifying information and general health care provider contact information for fewer than 50 other patients in the western United States.
The data breach also exposed contact information for an unknown number of Novocure employees, including job titles and phone numbers.
“No access to any of our medical treatment equipment was gained, our functionality was not compromised and all of our systems are fully functional,” Novocure added.
“The Company takes its obligation to protect the privacy and security of its patients’ information very seriously. The Company continues to review applicable regulatory and legal reporting requirements and will make any necessary notifications based on its findings, including to affected patients.”
A Novocure spokesperson was not immediately available for comment when BleepingComputer asked today how the attackers broke into its network and whether the company was in contact with them about paying a ransom.
This incident adds to a series of cyberattacks affecting healthcare companies in the last month.
Last month, healthcare software company Unlimited Technology Systems announced that more than 3.8 million people were affected by a data breach in October 2025, while healthcare IT company CareCloud said a data breach in March affected over 3.7 million people.
Recently, healthcare provider Nutex began investigating a data breach related to information theft from company servers, and pharmaceutical distribution giant McKesson uncovered a cybersecurity incident after extortion group ShinyHunters claimed the theft of 284 million patient records.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

