Oncology company Novocure has disclosed a cyberattack that exposed information associated with more than 1,400 U.S. cancer patients, along with contact details belonging to an undisclosed number of employees.
Novocure is a global healthcare technology company with more than 1,300 employees and operations across North America, Europe, the Middle East, and Asia. The company is best known for developing and commercializing Tumor Treating Fields (TTFields), a non-invasive electromagnetic therapy used to treat cancer tumors.
In a filing with the U.S. Securities and Exchange Commission (SEC), Novocure said it discovered the cybersecurity incident in mid-August after detecting unauthorized access to some of its information systems.
According to the company’s investigation, the attackers accessed records associated with more than 1,400 patients in the United States. The exposed information included patient identification numbers but did not contain names or other identifying details.
However, the personal information of fewer than 50 patients in the western United States was also accessed. That information included identifying details and general contact information for the patients’ healthcare providers.
The Novocure data breach also exposed contact information belonging to an undisclosed number of employees, including their job titles and telephone numbers.
Novocure said the cyberattack did not affect its medical equipment or operational capabilities.
“No access has been gained to any of our medical equipment, our operational capabilities are intact, and all of our systems are fully functional,” the company said.
“We take our obligation to protect the privacy and security of patient data very seriously. We continue to evaluate applicable regulatory and legal notification requirements and will provide all necessary notifications based on our findings, including to affected patients.”
Novocure did not immediately respond to BleepingComputer’s questions about how the attackers accessed its network or whether the company received a ransom demand.
The incident is the latest in a series of cyberattacks targeting healthcare organizations and technology providers in recent months.
Last month, healthcare software company Unlimited Technology Systems reported that an October 2025 data breach affected more than 3.8 million people. Healthcare IT provider CareCloud also disclosed that a March data breach impacted more than 3.7 million individuals.
More recently, healthcare services provider Nutex launched an investigation into a breach involving the theft of data from corporate servers. Pharmaceutical distribution giant McKesson also disclosed a cybersecurity incident after the ShinyHunters extortion group claimed to have stolen 284 million patient records.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



