Novocure Breach Exposes Data of 1,400+ Cancer Patients

Novocure, a global oncology company known for its Tumor Treating Fields (TTFields) cancer therapy, has disclosed a data breach that exposed information tied to more than 1,400 U.S. cancer patients.
In a filing with the U.S. Securities and Exchange Commission on September 1, the company said it discovered unauthorized access to some of its information systems in mid-August. An investigation found that attackers had accessed patient records containing ID numbers, though the company said most of these records did not include names or other directly identifying information.
For fewer than 50 patients in the western United States, the exposure was more serious: attackers accessed identifying information along with contact details for their healthcare providers. Employee data, including job titles and phone numbers, was also exposed, according to the filing.
Novocure, which has more than 1,300 employees across North America, Europe, the Middle East and Asia, said the incident did not affect its medical treatment devices. "No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional," the company said.
The company said it is continuing to assess its legal and regulatory notification obligations, meaning affected patients and employees may receive formal breach notices as that review concludes. Novocure's devices, including Optune Gio and Optune Lua, use low-intensity electric fields to disrupt tumor cell division in patients with glioblastoma and other cancers.
The breach adds to a string of cyberattacks on healthcare-adjacent companies in 2026, as attackers increasingly target medical data given its value on dark-web marketplaces and the sensitivity of the patients involved.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.