Novocure, the health technology company known for its Tumor Treating Fields therapy, has disclosed that a mid-August cyberattack exposed the data of more than 1,400 U.S. cancer patients. The company, which employs over 1,300 people and operates across North America, Europe, the Middle East, and Asia, filed the details with the U.S. Securities and Exchange Commission. The breach involved unauthorized access to some of its information systems, according to that filing.
The investigation found that attackers accessed more than 1,400 U.S. patient records containing ID numbers, though those records did not include patient names or other identifying data. However, for fewer than 50 patients located in the western U.S., the threat actors did access identifying information and general contact details for healthcare providers. The breach also exposed contact information, including job titles and phone numbers, for an undisclosed number of Novocure employees.
Novocure stated that no access was gained to its medical treatment devices, its ability to operate has not been compromised, and all systems remain fully functional. The company said it takes its obligation to safeguard patient privacy and security seriously and continues to evaluate regulatory and legal notification requirements. It added that it will make all required notifications based on its findings, including to impacted patients.
A Novocure spokesperson was not immediately available to answer questions about how the attackers breached the network or whether the company has been in contact with them regarding a ransom payment. The incident adds to a recent string of cyberattacks affecting the healthcare sector in the U.S. Last month, healthcare software company Unlimited Technology Systems disclosed a data breach from October 2025 that affected more than 3.8 million people, while healthcare IT firm CareCloud reported that a March breach impacted over 3.7 million individuals.
More recently, healthcare services provider Nutex began investigating a breach involving information theft from company servers, and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident after the ShinyHunters extortion group claimed the theft of 284 million patient data records. The Novocure incident underscores that overall prevention scores can mask what occurs after initial access, as once attackers use valid credentials, prevention effectiveness drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
More cybersecurity news from TechManNews.








