Novocure data breach affects more than 1,400 cancer patients

A major healthcare company’s sensitive patient data has been compromised in a cyberattack, leaving over 1,400 cancer patients vulnerable to potential identity theft and medical record tampering. Novocure, a global oncology firm specializing in non-invasive electromagnetic field therapy for cancer tumors, revealed that its network was breached in mid-August, exposing the private information of employees and patients.

The attack exposed sensitive data belonging to an undisclosed number of Novocure employees, including job titles and phone numbers. However, it’s reassuring to note that no medical treatment devices were accessed or compromised during the breach, and Novocure’s systems remain fully operational. The company’s patient records contained identification numbers but lacked names or other identifying information. Nevertheless, for a smaller subset of patients in the western United States, attackers obtained more sensitive information, including contact details for healthcare providers.

Novocure has taken swift action to contain the breach and is working with regulatory bodies to determine necessary notifications to affected parties. As part of its response, Novocure emphasized its commitment to safeguarding patient data and maintaining operational integrity. The company’s priority is to ensure that all regulatory requirements are met, including notifying impacted patients.

This incident underscores a growing trend in healthcare-related cyberattacks. In recent months, several major healthtech companies have reported breaches, affecting millions of individuals worldwide. Unlimited Technology Systems revealed a breach last month that exposed the data of over 3.8 million people, while CareCloud disclosed a March breach impacting more than 3.7 million patients. McKesson, another pharmaceutical distribution giant, recently acknowledged a cybersecurity incident following claims by the ShinyHunters extortion group.

Cybersecurity experts have noted that even with robust prevention measures in place, attackers can still gain access to sensitive systems using valid credentials. In fact, research suggests that once initial access is achieved, only 37% of subsequent actions are blocked by existing security controls. This highlights the importance of ongoing vigilance and adaptation in cybersecurity efforts.

As a healthcare-focused organization, Novocure’s breach serves as a stark reminder of the need for robust data protection measures within the industry. Patients rely on these companies to safeguard their sensitive information, making it essential that healthcare organizations prioritize security and take proactive steps to mitigate potential breaches. Individuals with affected records should remain vigilant and closely monitor their accounts for any suspicious activity.

To protect yourself from similar incidents, consider taking a proactive approach to your own data security:

* Regularly review and update your online accounts’ password policies

* Monitor your credit reports for any unauthorized activity

* Use multi-factor authentication whenever possible

* Stay informed about recent data breaches affecting healthcare companies

By staying aware of the latest cybersecurity threats and taking preventive measures, you can better safeguard your sensitive information.


Source: Bleeping Computer — 2026-09-01