---
title: "Novocure Reveals Major Breach of Cancer Patient Records"
date: 2026-09-01
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/09/novocure-discloses-data-breach-1500-patients.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Novocure Reveals Major Breach of Cancer Patient Records

Novocure disclosed on September 1, 2026 that a mid-August intrusion exposed internal records for more than 1,400 U.S. cancer patients. The oncology device maker said attackers reached patient ID numbers but never touched its treatment devices.

## What to Know?

- Novocure told the SEC that unauthorized access to its information systems exposed records for more than 1,400 U.S. patients.
- Patient ID numbers made up the bulk of it. Names and other identifying details were not in those records.
- Fewer than 50 patients in the western U.S. had additional identifying information accessed.
- Employee job titles and phone numbers were exposed, along with contact details for partner healthcare providers.
- Novocure said its treatment devices were untouched and that all its systems remain fully functional.

## How It Happened?

Novocure, which commercializes Tumor Treating Fields, a non-invasive electromagnetic cancer therapy, reported the access under Item 8.01 of a [Form 8-K](https://www.sec.gov/Archives/edgar/data/1645113/000164511326000065/nvcr-20260901.htm). The company activated its cybersecurity response plan, applied containment measures, and engaged independent forensic experts.

The filing names no intrusion vector. Novocure has not said whether phishing, a stolen credential, an internet-facing appliance, or a third-party system opened the door, and it has named no threat group.

The exposure splits into two tiers. More than **1,400** U.S. patient records held internal ID numbers with no names attached. Fewer than **50** patients in the western U.S. had identifying information accessed alongside provider contact details.

“**No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional,**” Novocure said in the filing.

> [$NVCR](https://x.com/search?q=%24NVCR&src=ctag&ref_src=twsrc%5Etfw) Cybersecurity Incident:  
>   
> NovoCure Ltd reported a cybersecurity incident that occurred in mid-August 2026, revealing unauthorized access to patient ID numbers for over 1,400 records but no patient names were exposed. The company activated its cybersecurity response, contains…
> 
> — SEC Filings Digest (@USCorpFilings) [September 1, 2026](https://x.com/USCorpFilings/status/2094746032479588440?ref_src=twsrc%5Etfw)

 ## What Novocure Has Not Answered?

The filing describes access to records, not confirmed theft of them. Unauthorized access establishes exposure. It does not establish that data left the network or reached a leak site.

Four questions stay open:

- **How the attackers entered, and how long they held access?**
- **Whether records were copied out, and whether an extortion demand followed?**
- **How many of the company’s more than 1,300 employees were exposed?**
- **When affected patients receive individual written notice?**

Patients on Tumor Treating Fields should treat any unsolicited call or email about their therapy as unverified until they confirm it with their care team. That habit helps reduce the risk of a follow-on phishing attempt, which usually lands well before the formal notice does.

## A Sector Under Sustained Attack

Novocure joins a run that has hit device makers Abbott, [Stryker](https://sqmagazine.co.uk/iran-hackers-claim-cyber-attack-stryker/), Medtronic and [Boston Scientific](https://sqmagazine.co.uk/boston-scientific-cyberattack-order-shipping-disruption/), drugmaker Novo Nordisk, and drug-delivery supplier West Pharmaceutical Services. Boston Scientific’s incident disrupted global operations in late August, a materially worse outcome.

Scale is not what makes this one notable. McKesson disclosed a breach after the ShinyHunters extortion group claimed **284 million** patient records, and healthcare IT firm CareCloud put its exposure at **3.7 million** individuals. Against those, 1,400 records barely registers in the sector’s [cyber threat statistics](https://sqmagazine.co.uk/cyber-threat-statistics/).

What separates **Novocure** is the product. Its therapy is worn against the body, so the reassurance the company led with concerned hardware integrity. Data came second.

## Why It Matters?

Novocure said it does not expect a material financial impact, which on the figures disclosed reads as defensible. The reputational math runs differently. An internal ID number stays anonymous only until it is joined to the file that decodes it, and that pairing is what an attacker sitting inside the same systems would go looking for.

**What comes next** is a notification clock. Novocure said it continues to evaluate applicable notification requirements, and under the **HHS Breach Notification Rule** covered entities have up to 60 days to notify individuals, with incidents affecting 500 or more people posted to the public portal run by OCR (the HHS Office for Civil Rights). Watch for an amended filing if forensic work widens the count, and for the kind of [litigation that followed the Allianz Life breach](https://sqmagazine.co.uk/allianz-life-data-breach-legal-suit/) to reach the western group whose names were exposed.