Novocure Reports Cyberattack Exposing Data of Over 1,400 Cancer Patients
AI-generated from multiple sources. Verify before acting on this reporting.
NEW YORK — Health technology firm Novocure announced on Monday that a cyberattack occurring in mid-August compromised the personal information of more than 1,400 U.S. cancer patients and an undisclosed number of employees. The breach marks a significant security incident for the company, which specializes in developing devices to treat cancer using tumor-treating fields.
Novocure disclosed the intrusion as part of its regulatory filing with federal authorities, stating that unauthorized actors gained access to its systems between August 12 and August 18, 2026. The company confirmed that the attackers exfiltrated data belonging to patients receiving treatment or seeking care within the United States. While the exact number of affected employees remains unspecified, Novocure indicated that the scope of the employee data breach is currently under assessment.
The compromised information includes names, dates of birth, and Social Security numbers for some individuals. In certain cases, the stolen data also contained medical record numbers and details regarding specific cancer diagnoses and treatment plans. Novocure emphasized that no financial account numbers or credit card information were accessed during the incident.
Upon discovering the breach, the company immediately engaged third-party cybersecurity experts to investigate the scope of the intrusion and secure its networks. The investigation is ongoing, and Novocure has notified relevant law enforcement agencies. The firm stated it is working with legal counsel to determine the appropriate course of action regarding patient notifications and regulatory compliance.
The attack occurred without a publicly stated motive or attribution to any specific threat actor. Novocure has not identified whether the breach was the result of ransomware, phishing, or an exploit of a software vulnerability. The company noted that it is reviewing its security protocols to prevent future incidents.
Patients whose data was exposed will receive notification letters detailing the nature of the breach and steps they can take to protect their identities. Novocure has established a dedicated call center to assist affected individuals with questions regarding the incident. The firm also plans to offer credit monitoring services to those impacted, though specific terms of the service have not been finalized.
The health technology sector has faced increasing scrutiny over data security in recent years, as digital health records become more prevalent. This incident adds to a growing list of high-profile breaches affecting medical organizations across the United States. Novocure shares are expected to face volatility following the disclosure, as investors assess the potential financial and reputational impact of the breach.
As the investigation continues, questions remain regarding the full extent of the data loss and whether additional patient records were accessed beyond the initial count. Novocure has committed to providing further updates as more information becomes available.