Novocure breach exposes 1,400 patient IDs
Healthtech firm Novocure reveals a mid-August cyberattack exposed data of over 1,400 U.S. cancer patients and some employees.
The fallout from a mid-August cyberattack at oncology company Novocure is becoming clearer: more than 1,400 U.S. cancer patients had records accessed, according to a filing with the U.S. Securities and Exchange Commission (SEC). The company, known for its Tumor Treating Fields (TTFields) therapy, says the breach also touched an undisclosed number of employees.
Patient data exposure details
Novocure, a global oncology firm with more than 1,300 employees and operations across North America, Europe, the Middle East, and Asia, disclosed the incident in an SEC filing. The unauthorized access was first detected in mid-August, and a follow-up investigation revealed the scope of the data exposure.
According to the company, attackers accessed over 1,400 U.S. patient records containing ID numbers, but those records did not include patient names or other identifying data. However, for fewer than 50 other patients in the western U.S., the threat actors accessed identifying information and general contact information for healthcare providers.
The breach also exposed contact information for an undisclosed number of Novocure employees, including job titles and phone numbers.
No device compromise, company says
In a statement, Novocure emphasized that the attack did not affect its medical treatment devices. "No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional," the company said.
It also pledged to continue evaluating regulatory and legal notification requirements. "The Company takes its obligation to safeguard privacy and security of its patients' data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients," Novocure added.
Investigation and response questions
A Novocure spokesperson was not immediately available for comment when BleepingComputer asked earlier today how the attackers breached its network and whether the Company has been in contact with them about paying a ransom.
The company has not disclosed how the attackers gained access or whether a ransom demand was made. The SEC filing marks the primary public disclosure of the incident so far.
Healthcare sector under siege
The Novocure incident adds to a series of cyberattacks affecting healthcare companies over the last month.
Last month, healthcare software company Unlimited Technology Systems disclosed that a data breach in October 2025 affected more than 3.8 million people, while healthcare IT company CareCloud said that a March data breach has impacted over 3.7 million individuals.
More recently, healthcare services provider Nutex began investigating a data breach involving information theft from company servers, and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident after the ShinyHunters extortion group claimed the theft of 284 million patient data records.
Key data points from the Novocure breach
- More than 1,400 U.S. patient records accessed, containing ID numbers but no names or identifying data.
- Fewer than 50 additional patients in the western U.S. had identifying information and provider contact details accessed.
- An undisclosed number of employee contact records, including job titles and phone numbers, were exposed.
- Novocure has more than 1,300 employees globally.
Why it matters
For cancer patients whose records were touched, the exposure of ID numbers — even without names — can still be a piece in a larger identity puzzle when combined with other leaked data. The breach underscores how healthcare organizations, with their troves of sensitive medical and personal information, remain a prime target for attackers. Novocure's ability to continue operating may be intact, but the incident suggests that even companies with advanced medical technology are not immune to network intrusions. The coming weeks will likely show whether this becomes part of a broader pattern of healthcare breaches, or a one-off event. For patients, the advice remains: watch for any unusual activity related to their medical records or insurance claims.
Sources
- BleepingComputer Original source
Continue Reading
ATM jackpotting ring pleads guilty in Kansas
Five Venezuelans admit to failed ATM malware attacks; U.S. urges banks to adopt anti-jackpotting tech.
Cronos Restart Follows $74M Lending Exploit
Cronos blockchain resumes after price manipulation drained $74M from Tectonic lending app.
Nigerian sextortion suspects face US charges after teen deaths
Two Nigerian men extradited to the US over sextortion schemes linked to deaths of two minors face life sentences.