Novocure Says Cancer Patient Data Exposed in August Break-In

The oncology device maker told the SEC that intruders reached records for more than 1,400 U.S. patients, though treatment devices were untouched.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit government-style operations center, rows of empty analyst workstations with monitors showing ab
Share

Key points

  • Novocure, a global cancer-therapy company, disclosed a cyberattack from mid-August 2025 in a filing with the U.S. Securities and Exchange Commission.
  • Attackers reached records for more than 1,400 U.S. cancer patients, held as ID numbers without names attached.
  • Fewer than 50 patients in the western U.S. had identifying details and their healthcare providers' contact information exposed.
  • Some employee contact details, job titles and phone numbers were also taken.
  • Novocure says none of its medical treatment devices were touched and its systems still work normally.

Novocure, the company behind Tumor Treating Fields (a wearable therapy that uses low-level electric fields to slow cancer cell growth), has told U.S. regulators that hackers broke into some of its computer systems in mid-August. The disclosure came in a filing with the U.S. Securities and Exchange Commission, the agency public companies must notify about serious incidents.

The breach was first reported by BleepingComputer.

In practice, this is a fairly typical mid-sized healthcare intrusion: sensitive but partial patient data taken, corporate email and HR-style details scraped, no sign the attackers reached the machines that actually treat people.

What was actually taken?

The hackers reached records for more than 1,400 U.S. cancer patients, but those records held only patient ID numbers, not names or addresses. A much smaller group, fewer than 50 patients in the western United States, had their identifying information exposed along with contact details for the doctors and clinics treating them.

Some Novocure employees were also caught up in it. The company says contact information, job titles and phone numbers for staff were exposed, though it has not said how many.

Novocure has not named the group behind the attack, and has not said whether a ransom was demanded.

Were the medical devices affected?

No. Novocure was clear on this point: "No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional."

That matters because Novocure's product sits on patients' bodies. A device compromise would be a very different story. The failure mode here is data theft from corporate systems, not tampering with therapy.

What should patients do?

For the roughly 1,400 patients whose records held only ID numbers, the practical risk is low: without a name attached, an ID number is hard to abuse. The smaller group of under 50 patients whose names and provider details were taken should watch for two things: unexpected calls or emails that seem to know medical details about them, and any suspicious activity in insurance statements.

Novocure says it will notify affected patients directly where the law requires it.

A rough month for healthcare

This is the latest in a run of healthcare breaches. Unlimited Technology Systems disclosed an October 2025 incident affecting more than 3.8 million people. CareCloud reported a March breach hitting over 3.7 million. Pharmaceutical distributor McKesson has confirmed a cybersecurity incident after the ShinyHunters extortion crew claimed to hold 284 million patient records, a figure the group has not substantiated.

Company Disclosed People affected
Novocure Nov 2025 1,400+ patients, some staff
Unlimited Technology Systems Oct 2025 3.8 million
CareCloud 2025 3.7 million
McKesson Nov 2025 Under investigation

One thing the post-mortem will almost certainly say: the corporate side of a medical company is a softer target than the regulated device side, and attackers know it. Operational takeaway: segment the office network from anything touching patients, and assume employee contact lists are already stolen goods.

© 2026 Threat Vectr