Novocure, an oncology therapy company, discovered a cyberattack in August 2026 that exposed identification numbers for more than 1,400 U.S. cancer patients, detailed identifying information for fewer than 50 patients, and contact details for an undisclosed number of employees. Affected individuals should monitor credit reports, watch for phishing attempts, and consider a fraud alert or credit freeze as a first step.
| Company | Novocure |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Patient Identification Numbers, Patient Identifying Information, Healthcare Provider Contact Information, Employee Job Titles, Employee Phone Numbers |
| People Affected | More than 1,400 individuals |
| Attack Method | Unauthorized Network Access |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the Novocure Data Breach?
Novocure, a company that develops electromagnetic field therapy for cancer treatment, has confirmed a cyberattack that exposed sensitive patient and employee information. The company discovered unauthorized access to its information systems in August 2026. As a result, it launched an internal investigation to determine the scope of the intrusion.
According to the company’s disclosure, attackers gained access to certain internal systems before the breach was detected. Novocure has not publicly explained exactly how the attackers first got in. However, the company confirmed that the intrusion allowed outside parties to view files containing patient and staff information.
Following discovery, Novocure brought in investigators to assess what data the attackers accessed. This forensic review determined that more than 1,400 U.S. patient records were viewed, along with a smaller set of records containing more detailed identifying information. In addition, the company reported the breach to federal regulators in September 2026.
Notably, Novocure stated that its medical treatment devices were not accessed during the incident. The company also said its operations were not disrupted and that all systems remain fully functional. This distinction matters because it clarifies that the breach affected data systems rather than the therapy equipment used in patient care.
Who was affected?
The Novocure data breach affects two distinct groups: cancer patients and company employees. Because Novocure operates globally, the incident has an international footprint, but this report focuses on the impact to U.S. individuals whose data was accessed.
More than 1,400 U.S. patients had records accessed that included identification numbers. Separately, fewer than 50 patients in the western United States had more detailed personal and provider contact information exposed. This means the severity of exposure varies significantly across the affected population.
Novocure also confirmed that employee data was exposed, though the exact number of affected staff members hasn’t been publicly disclosed. Employee information included job titles and phone numbers. Since some of the affected patients are undergoing cancer treatment, the breach raises particular concern for a medically vulnerable population.
What Information Was Potentially Exposed?
The categories of information exposed in this breach differ depending on which group of individuals is involved. For most patients, the exposure was limited, but for a smaller subset, more sensitive identifying details were involved.
- Patient identification numbers (for over 1,400 U.S. patients)
- Patient identifying information, for fewer than 50 individuals
- General contact information for healthcare providers
- Employee job titles
- Employee phone numbers
For the majority of affected patients, the exposed records reportedly did not include names or other identifying details. This limits the immediate risk for that larger group. However, for the smaller group of patients whose identifying information was accessed, the risk profile is considerably higher.
When identifying details are combined with the fact that these are cancer patients, there’s a heightened risk of targeted phishing or scam attempts. Fraudsters sometimes exploit health-related anxiety to trick victims into revealing further personal or financial details. As a result, affected patients should remain cautious about unexpected communications referencing their treatment or health status.
What is the company doing?
Novocure has stated that it takes data privacy obligations seriously and is working to determine its legal notification duties. The company said it will notify all impacted patients based on the findings of its investigation. In addition, Novocure confirmed that its systems remain operational and that patient care through its treatment devices was never at risk.
The company disclosed the incident in a filing with the U.S. Securities and Exchange Commission, satisfying federal disclosure obligations for publicly traded companies. Novocure indicated it continues to evaluate applicable regulatory and legal requirements as the investigation proceeds. This suggests further notifications, including formal letters to affected patients and employees, are likely still forthcoming.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. Because identifying information was exposed for a subset of patients, monitoring helps catch fraud attempts early. You can request free reports from each of the three major credit bureaus annually.
In addition, consider spacing out your requests throughout the year so you have ongoing visibility into your credit file. If you notice suspicious activity, report it immediately to the credit bureau and consider filing a police report. Early detection often limits the damage from identity theft.
Watch for Phishing and Scam Attempts
Given the health-related nature of this breach, affected patients should be especially alert to phishing emails or phone calls referencing their treatment. Scammers often use stolen health information to make fraudulent messages appear legitimate. Therefore, never click links or share personal details in response to unsolicited messages.
Instead, verify any communication directly with Novocure or your healthcare provider using contact information you already trust. If a message pressures you to act quickly or threatens negative consequences, treat that as a red flag. Legitimate healthcare organizations rarely demand urgent action through email or text.
Consider a Fraud Alert or Credit Freeze
Because a portion of affected patients had identifying information exposed, placing a fraud alert on your credit file adds an extra layer of protection. A fraud alert requires lenders to verify your identity before opening new credit in your name. This step is free and typically lasts one year.
For stronger protection, you can also request a credit freeze, which restricts access to your credit file entirely. This makes it much harder for identity thieves to open new accounts using your information. While a freeze requires you to lift it temporarily when applying for credit, it offers significant peace of mind.
Protect Your Healthcare Identity
Because this breach involves a cancer treatment provider, affected patients should also watch for signs of medical identity theft. This can include unfamiliar charges on insurance statements or notices about medical services you never received. Reviewing insurance explanation-of-benefits statements regularly can help catch this early.
If you spot anything unusual, contact your insurance provider and healthcare provider right away. You may also want to request a copy of your medical records to confirm accuracy. Addressing discrepancies quickly can prevent long-term complications with your medical history and insurance coverage.
