Key Takeaways
- More than 1,400 U.S. patients had internal Novocure identification numbers exposed, while fewer than 50 patients had additional identifying information affected.
- Novocure said its Tumor Treating Fields devices were not accessed, operations were not disrupted, and all systems remain functional.
- The incident highlights the growing use of data theft and extortion tactics against healthcare and medical technology businesses.
Novocure has disclosed unauthorized access to internal information systems that exposed limited patient, employee, and healthcare provider data. The oncology technology business detected the intrusion through a subsidiary in mid-August 2026, according to a Form 8-K filed with the U.S. Securities and Exchange Commission on September 1.
After discovering the activity, Novocure activated its incident response plan, introduced containment measures, and brought in third-party cybersecurity forensic specialists. The investigation remains underway, and Novocure has not identified the threat actor or described the initial point of entry. It also has not said whether ransomware, an extortion demand, or malware was involved.
The most significant disclosure concerns more than 1,400 U.S. patients. For that group, the exposed information was limited to internal company identification numbers, without patient names or other identifying data. Fewer than 50 patients in the United States had additional identifiers exposed. Reuters reported that the affected records involved more than 1,400 U.S. patients overall.
General contact information for U.S. healthcare providers working with Novocure was also affected. The compromised systems contained employee contact details, including job titles and telephone numbers, although Novocure did not disclose the number of employees involved. While contact information may appear less sensitive than clinical records, attackers can use organizational details to construct convincing phishing, impersonation, and social-engineering campaigns.
Crucially, Novocure found no unauthorized access to its medical treatment devices. The company said operations were unaffected and all systems remained fully functional. It does not currently expect the incident to have a material effect, or a reasonably likely material effect, on its financial condition or operating results. That assessment could change as forensic work proceeds, but the separation between business systems and treatment technology appears to have limited the immediate clinical risk.
Novocure employs approximately 1,300 people worldwide, with its global headquarters in Baar, Switzerland, and U.S. headquarters in Portsmouth, New Hampshire. Its Tumor Treating Fields technology uses low-intensity, alternating electrical fields to disrupt cancer-cell division. For patients relying on such equipment, the primary concern is whether treatment was interrupted. In this case, Novocure confirmed it was not.
The incident occurs during a difficult period for healthcare security. The American Hospital Association reported that healthcare and public health was the leading critical-infrastructure sector for ransomware and other cyberthreats in 2025, recording 460 ransomware attacks and 182 data breaches, totaling 642 cyber events.
Separate HHS Office for Civil Rights data analyzed by the HIPAA Journal identified 697 large healthcare breaches affecting at least 61.5 million people in 2025. Providers accounted for 523 reports, health plans for 56, clearinghouses for two, and business associates for 128.
Attackers do not need to disable medical equipment to create business and compliance problems. Data theft alone can trigger notification work, legal review, forensic costs, tougher partner scrutiny, and follow-on fraud attempts. Extortion-only incidents are also becoming more visible, with criminals stealing information and demanding payment without encrypting production systems.
Novocure’s relatively contained impact contrasts with broader disruptions in the sector, such as the 2025 ransomware attack that hit kidney dialysis provider DaVita.
For medical technology leaders, network segmentation between corporate systems and treatment environments can help limit operational consequences, while tighter identity controls, subsidiary oversight, data minimization, and tested response procedures can reduce exposure. Novocure’s devices kept operating, and the ongoing investigation will determine whether its containment also prevented a limited intrusion from developing into a more consequential breach.
⬇️