Novocure disclosed that unauthorized actors accessed certain company information systems in mid-August, exposing data associated with more than 1,400 U.S. cancer patients. The accessed records contained patient ID numbers but reportedly did not include names or other identifying information; attackers also obtained identifying information for fewer than 50 patients in the western United States and general contact details for healthcare providers.
The incident also exposed contact information, job titles, and phone numbers for an undisclosed number of employees. Novocure said its medical treatment devices were not accessed, operations were not disrupted, and systems remain functional as the company assesses notification obligations.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
ShinyHunters claimed it had attacked Novocure and published a purported 33 GB archive of files allegedly stolen from the company. Novocure had not officially attributed the breach to the group.
In mid-August 2026, Novocure identified unauthorized access to certain information systems. The incident exposed patient and employee-related information, while its medical treatment devices and operational systems were not accessed or disrupted.
Novocure disclosed in an SEC filing that attackers accessed patient ID numbers for more than 1,400 U.S. cancer patients and identifying information for fewer than 50 additional western U.S. patients, as well as healthcare-provider and employee contact information. The company said it was assessing notification obligations and would notify affected parties as required.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcehipaajournal.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourceorkl.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.