Oncology Firm Novocure Announces Cyberattack and Data Breach
The medical technology and oncology company Novocure has recently confirmed that patient and employee data were exposed in a recent cyberattack. Novocure is a publicly traded company with approximately 1,300 employees worldwide. Its global HQ is in Baar, Switzerland, and its U.S. headquarters is in Portsmouth, New Hampshire. The company has developed a novel non-invasive cancer treatment called Tumor Treating Fields (TTFields), which uses low-intensity, alternating electrical fields to disrupt the division of cancer cells.
Novocure explained in a September 1, 2026, Form-8K filing with the U.S. Securities and Exchange Commission (SEC), that it became aware of unauthorized access to some of its information systems via a subsidiary in mid-August 2026. Its incident response plan was activated, along with containment measures, and an investigation was launched, with assistance provided by third-party cybersecurity forensics experts.
While employee and patient data were stored on the compromised systems, the impact of the data breach was limited. Based on the investigation to date, approximately 1,400 U.S. patients had data exposed in the incident. The breach was limited to internal company ID numbers – no patient names or other identifying data were exposed. Fewer than 50 other patients in the Western United States had additional identifying information exposed, along with general contact information for all U.S. healthcare providers that the company works with, and general contact information for Novocure employees, including job titles and phone numbers. Novocure did not disclose how many employees had their contact information exposed in the incident.
Novocure said there was no unauthorized access to any of its medical treatment devices, no impact to operations, and all systems are fully functional. At the time of issuing the filing, Novocure said it does not believe that the incident will have any material impact or reasonably likely impact on its financial condition or results of operations, although the investigation into the incident is ongoing. The threat group behind the attack and the nature of the incident were not disclosed.
Several medical technology companies have experienced cyberattacks this year, including Unlimited Technology Systems, CareCloud, Boston Scientific, Medtronic, Stryker, Abbot Laboratories, and iRhythm, although in this case, the impact appears to be limited. Other medtech companies have not been so fortunate. The cyberattacks on Unlimited Technology Systems and CareCloud involved unauthorized access to systems containing 3.8 million and 3.7 million patient records respectively, and the cyberattack on Boston Scientific disrupted operations globally.



