A devastating data breach has struck cancer treatment company Novocure, exposing sensitive information of over 1,400 US cancer patients and an undisclosed number of employees. The attack, which occurred in mid-August, highlights the ongoing vulnerability of healthcare organizations to cyber threats.
Novocure, a global oncology company with operations in multiple continents, is known for its non-invasive electromagnetic field therapy called Tumor Treating Fields (TTFields). While the company has been at the forefront of cancer treatment innovation, it seems that Novocure’s cybersecurity defenses were no match for the attackers. According to an SEC filing, unauthorized access was discovered after a thorough investigation into the incident.
The breach exposed patient records containing ID numbers, but fortunately did not include names or other identifying information for over 1,400 patients. However, for a smaller number of patients in the western US, the attackers accessed more sensitive information, including contact details for healthcare providers. Additionally, an undisclosed number of Novocure employees had their contact information, including job titles and phone numbers, compromised.
Novocure has assured that no access was gained to its medical treatment devices, and all systems are fully functional. However, this incident serves as a stark reminder of the importance of robust cybersecurity measures in the healthcare sector. With the rise of cyberattacks on healthcare companies over the past month, it’s clear that these organizations need to invest more in protecting their patients’ sensitive data.
This breach is not an isolated incident; several other healthcare companies have been targeted by attackers in recent months. Unlimited Technology Systems, a healthcare software company, disclosed a data breach affecting 3.8 million people last month. CareCloud, another healthcare IT firm, revealed that a March data breach impacted over 3.7 million individuals. The frequency and severity of these attacks highlight the need for healthcare organizations to prioritize cybersecurity.
The takeaway from this incident is clear: even with robust prevention measures in place, attackers can still gain access to sensitive information if they have valid credentials. As a result, it’s essential for both patients and employees to be vigilant about protecting their data and for companies like Novocure to invest in continuous monitoring and incident response planning.
In light of this breach, we urge all readers to take steps to safeguard their personal data, including being cautious when sharing sensitive information online and regularly reviewing account security settings. By staying informed and taking proactive measures, we can reduce the impact of these devastating cyberattacks on individuals and communities.
Source: Bleeping Computer — 2026-09-01