Skip to main content
Emerging ThreatsData Breaches

Novocure Breach Exposes Over 1,400 US Cancer Patient Records

Hospital corridor with medical office door ajar, patient info sheet blurred in foreground.

"No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional," Novocure added.

Novocure: scope, discovery, and immediate public disclosures

Novocure, a global oncology company with more than 1,300 employees and operations in North America, Europe, the Middle East, and Asia, disclosed in a filing with the U.S. Securities and Exchange Commission (SEC) that it discovered unauthorized access to some of its information systems in mid‑August. The company — known for inventing and commercializing Tumor Treating Fields (TTFields), a non‑invasive electromagnetic field therapy for cancer tumors — said a follow‑up investigation identified patient and employee data in the attackers' reach.

Patient records: numbers, content, and geographic detail

According to Novocure’s investigation, attackers accessed over 1,400 U.S. patient records that contained ID numbers, but those records did not include patient names or other identifying data. The company also said that for fewer than 50 other patients in the western U.S., the threat actors accessed identifying information and general contact information for healthcare providers. Novocure said it continues to evaluate applicable regulatory and legal notification requirements and "will make all required notifications based on its findings, including to impacted patients."

Employee contact information and operational claims

The breach also exposed contact information for an undisclosed number of Novocure employees, including job titles and phone numbers. Despite the exposure, Novocure stated that "our ability to operate has not been compromised and all of our systems are fully functional." A Novocure spokesperson was not immediately available for comment when BleepingComputer asked earlier today how the attackers breached its network and whether the company has been in contact with them about paying a ransom.

This breach alongside recent healthcare incidents

Novocure’s disclosure arrives amid a string of reported cyber incidents affecting healthcare organizations. Last month, Unlimited Technology Systems said a data breach in October 2025 affected more than 3.8 million people. Healthcare IT company CareCloud disclosed that a March data breach impacted over 3.7 million individuals. Healthcare services provider Nutex began investigating a data breach involving information theft from company servers, and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident after the ShinyHunters extortion group claimed the theft of 284 million patient data records.

The reporting also highlighted a defensive shortfall captured in the Blue Report 2026: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The Blue Report measures defenses technique by technique across 338 million simulations run in customer production environments.

How technologists, regulators, and patients are likely to respond

  • Technologists and security teams: expect heightened attention to credential misuse and post‑access detection, given the Blue Report’s finding that prevention falls once valid credentials are in play. Technical teams will want to confirm the attack vector and whether credential compromise played a role — details Novocure has not publicly supplied.
  • Regulators and legal teams: Novocure has said it "continues to evaluate applicable regulatory and legal notification requirements" and will notify impacted patients where required. That review will determine the timing and substance of formal notices tied to state, federal, or sectoral privacy rules referenced in the company’s SEC filing.
  • Patients and healthcare providers: more than 1,400 U.S. patient records with ID numbers were accessed, and fewer than 50 western U.S. patients had identifying information exposed along with general contact details for healthcare providers. Those individuals and their providers are the immediate focus for notification and any follow‑up offered by Novocure.

Novocure’s public account fixes two facts while leaving technical ones open: it asserts devices and core operations were not touched, and it confirms the exposure of both patient and employee contact data; it does not describe how attackers gained entry or whether extortion demands were made. The company’s SEC filing and its stated commitment to make required notifications set a procedural path forward, but the absence of technical detail echoes a broader pattern — one the Blue Report and the recent string of healthcare incidents underscore — in which disclosure often precedes a full public accounting of methods, scope, and remediation.

Original story