Novocure Data Breach Exposes Information of Over 1,400 Cancer Patients
Healthcare technology company confirms mid-August cyberattack compromises patient and employee data

Key Takeaways
- Novocure confirmed a mid-August 2026 cyberattack exposing data of over 1,400 U.S. cancer patients.
- The exact number of affected employees and specific data types exposed remain undisclosed.
- No specific exploitation details, ransomware claims, or attack vectors have been publicly reported.
- Breach notification and incident response processes are reportedly underway.
- The incident highlights the ongoing cybersecurity risks facing healthcare technology and patient data systems.
Quick answers
- What happened?
- Novocure, a healthtech company specializing in cancer treatment technologies, confirmed a cyberattack in mid-August 2026 that exposed the data of more than 1,400 U.S. cancer patients and an undisclosed number of employees. The breach was first reported publicly on September 1, 2026.
- What should defenders do?
- Novocure is likely conducting incident response activities and breach notifications. Affected individuals and employees should monitor for official notification communications from Novocure. General best practices include remaining vigilant against phishing, monitoring account statements, and following any guidance issued by Novocure regarding credit monitoring or protective measures.
Novocure has confirmed that a cyberattack occurring in mid-August 2026 resulted in a data breach affecting more than 1,400 U.S. cancer patients and an undisclosed number of employees. According to reporting by BleepingComputer published on September 1, 2026, the incident involved the exposure of stored data, though specific details regarding the types of patient information accessed or the attack vector used have not been disclosed. The company has not specified the exact number of affected employees. Novocure stated that breach notification processes and incident response activities are underway. As of the reporting date, no specific exploitation details or ransomware claims have been publicly associated with the incident. The full scope of data exposed and the method of initial compromise remain under investigation.
Security Details
The breach involved exposure of stored data related to Novocure's patients and employees. Specific vulnerability details, attack vectors, and the precise categories of compromised data have not been disclosed in available reporting. The incident was reported publicly on September 1, 2026, following the mid-August 2026 attack timeframe.
Mitigation
Novocure is likely conducting incident response activities and breach notifications. Affected individuals and employees should monitor for official notification communications from Novocure. General best practices include remaining vigilant against phishing, monitoring account statements, and following any guidance issued by Novocure regarding credit monitoring or protective measures.
Sources
BleepingComputer
Novocure data breach affects more than 1,400 cancer patients
Sep 1, 2026 · 14:28
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



