TechNewsReel
Live

Novocure Cyberattack Exposes Records of 1,400+ U.S. Cancer Patients

The oncology firm confirmed unauthorized access to internal systems, triggering privacy concerns for a vulnerable patient population.

TechNewsReel Newsroom · September 10, 2026

Global oncology company Novocure confirmed a mid-August cyberattack that compromised the personal records of more than 1,400 cancer patients in the United States. The breach highlights the persistent vulnerability of medical technology firms to targeted data theft.

According to company disclosures and reports from BleepingComputer and HIPAA Journal, the incident involved unauthorized access to Novocure's internal information systems. The exposed data included patient ID numbers, as well as sensitive information belonging to the company's employees and healthcare providers. The hacking group ShinyHunters claimed responsibility for the intrusion, asserting they released a 33-gigabyte archive of stolen files.

Industry Context

Novocure is a publicly traded medical technology firm specializing in non-invasive electromagnetic field therapy for cancer tumors, employing roughly 1,300 people globally. This breach is part of a wider, escalating trend of cyberattacks targeting the medtech and healthcare sectors. Attackers frequently target these organizations because sensitive patient health information (PHI) commands a high premium on the dark web compared to standard consumer data.

Privacy Implications

The breach is particularly critical given the vulnerability of the affected population. While Novocure stated that its medical devices remained secure and that clinical operations were not disrupted, the exposure of patient IDs and employee data creates significant privacy risks. The company emphasized that "protecting the privacy and security of patient data remains a priority," yet the incident raises immediate questions regarding HIPAA compliance and the adequacy of the firm's internal safeguards.

What's Next

Industry analysts are monitoring the situation to see if the leaked 33-gigabyte archive contains more granular health data than the patient IDs initially reported. While the company has addressed the immediate technical breach, the long-term fallout typically involves regulatory scrutiny and potential class-action litigation as affected patients and employees seek to determine the full extent of their data exposure. The incident serves as a stark reminder that for medtech firms, the security of the data pipeline is as critical as the security of the medical devices themselves.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.