
Novocure, a global oncology company that develops Tumor Treating Fields therapy for cancer patients, has disclosed a cybersecurity incident that exposed internal records tied to more than 1,400 patients in the United States, along with contact information for an undisclosed number of employees.
The company, which has more than 1,300 employees and operations spanning North America, Europe, the Middle East and Asia, reported the breach in a filing with the U.S. Securities and Exchange Commission. Novocure said it identified unauthorized access to certain information systems in mid-August.
A subsequent investigation found that attackers obtained patient ID numbers for more than 1,400 individuals in the U.S., though those records did not include patient names or other identifying details. A smaller group of patients in the western United States, fewer than 50, had their identifying information and healthcare provider contact details accessed.
The intrusion also compromised employee contact information, including job titles and phone numbers, though Novocure did not specify how many employees were affected.
Novocure said its medical treatment devices were not accessed during the breach and that its operations have continued without interruption. The company stated that all of its systems remain fully functional.
The company said it is reviewing its notification obligations under applicable regulations and plans to inform affected patients and other required parties based on the outcome of that review. Novocure emphasized that protecting the privacy and security of patient data remains a priority.
Details on how the attackers breached Novocure’s network, and whether the company has engaged with them over a potential ransom demand, have not been disclosed.
The incident is part of a broader wave of cyberattacks targeting the healthcare industry in recent months. Healthcare software provider Unlimited Technology Systems recently disclosed that a breach dating to October 2025 affected more than 3.8 million people, while healthcare IT company CareCloud reported that a breach in March affected more than 3.7 million individuals. Healthcare services provider Nutex has also begun investigating a breach involving the theft of information from its servers, and pharmaceutical distributor McKesson disclosed a cybersecurity incident after the extortion group ShinyHunters claimed to have stolen 284 million patient records.
Other companies in the healthcare and pharmaceutical sectors that have faced cyberattacks in this period include medical device manufacturers Abbott, Stryker, Medtronic and Boston Scientific, along with drugmaker Novo Nordisk and drug-delivery equipment supplier West Pharmaceutical Services.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543