CSIDB logo
Incident

Novocure

Incident posture

Attack window
Aug 2026
Location
Switzerland
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-03 12:00

Linked entities

Victim
Novocure
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2026
Discovered
Aug 2026
Disclosed
Sep 2026
Resolved
Pending

Summary

A publicly traded medical technology and oncology company discovered unauthorized access to some of its information systems through a subsidiary in mid-August, prompting activation of its incident response plan and engagement of third-party cybersecurity forensics experts. The breach exposed internal company ID numbers for approximately 1,400 U.S. patients, while fewer than 50 additional patients in the western United States had further identifying information compromised. General contact information for U.S. healthcare providers and for company employees, including job titles and phone numbers, was also exposed, though no medical treatment devices were accessed and no operational impact occurred. All systems remained fully functional throughout the incident, and the investigation is ongoing, with the threat group responsible and the specific nature of the attack not publicly disclosed.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On September 1, 2026, Novocure, a publicly traded medical technology and oncology company headquartered in Baar, Switzerland, with U.S. operations centered in Portsmouth, New Hampshire, filed a Form 8-K with the U.S. Securities and Exchange Commission disclosing a recent cyberattack and data breach. The company, which employs approximately 1,300 people worldwide and developed the Tumor Treating Fields (TTFields) non-invasive cancer treatment platform, reported that it became aware of unauthorized access to some of its information systems in mid-August 2026. The initial intrusion was identified within a subsidiary, after which Novocure activated its incident response plan and implemented containment measures. Third-party cybersecurity forensics experts were engaged to assist with the investigation, the details of which were still ongoing at the time of the filing.

The compromised systems contained both employee and patient data, though the company emphasized that the impact of the data breach was limited. Based on the investigation available at the time of disclosure, approximately 1,400 U.S. patients had their information exposed. For the vast majority of these individuals, the breach was confined to internal company identification numbers, with no patient names or additional identifying data involved. However, fewer than 50 additional patients located in the Western United States had more detailed identifying information exposed as a result of the incident. Beyond patient data, the breach also involved general contact information for all U.S. healthcare providers with whom Novocure works, as well as general contact information for Novocure employees, including their job titles and phone numbers. The company did not specify how many employees were affected by this latter category of exposure.

Novocure stated that there was no unauthorized access to any of its medical treatment devices, and that the incident did not disrupt operations. All systems remained fully functional following the breach. The company further indicated that it did not believe the incident would have a material impact, or a reasonably likely material impact, on its financial condition or results of operations, although it noted that the investigation remained active. The identity of the threat group behind the attack and the specific nature of the incident were not disclosed in the filing or in subsequent public statements, leaving those details unresolved at the time of reporting.

The cyberattack on Novocure occurred during a period in which several other medical technology companies experienced security incidents throughout 2026. Notable comparable cases included breaches at Unlimited Technology Systems and CareCloud, which involved unauthorized access to systems containing 3.8 million and 3.7 million patient records respectively, and a cyberattack on Boston Scientific that disrupted global operations. Other affected companies in the same timeframe included Medtronic, Stryker, Abbot Laboratories, and iRhythm. Despite this broader context of heightened targeting within the medical technology sector, the data exposure at Novocure was characterized as comparatively limited in scope, affecting a relatively small subset of patient records and primarily non-clinical contact information rather than comprehensive personal or medical data.

Sources

Sources available to members: 1 source.

CSIDB