BTC$84,521-0.54% LTC$68.72+1.12% XMR$536.90-2.07%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 1, 2026 · 2 min read · Original story

Novocure data breach affects more than 1,400 cancer patients

Novocure data breach affects more than 1,400 cancer patients

Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack.

Novocure is a global oncology company with more than 1,300 employees and operations in North America, Europe, the Middle East, and Asia, known for inventing and commercializing Tumor Treating Fields (TTFields), a non-invasive electromagnetic field therapy for cancer tumors.

The Company disclosed in a filing with the U.S. Securities and Exchange Commission (SEC) that it discovered the incident after unauthorized access to some of its information systems in mid-August.

According to a follow-up investigation, the attackers accessed over 1,400 U.S. patient records with ID numbers, but those records didn't contain patient names or other identifying data. However, for fewer than 50 other patients in the western U.S, the threat actors accessed identifying information and general contact information for healthcare providers.

The data breach also exposed contact information for an undisclosed number of Novocure employees, including job titles and phone numbers.

"No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional," Novocure added.

"The Company takes its obligation to safeguard privacy and security of its patients' data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients."

A Novocure spokesperson was not immediately available for comment when BleepingComputer asked earlier today how the attackers breached its network and whether the Company has been in contact with them about paying a ransom.

Claimed by ShinyHunters

While Novocure has yet to attribute this breach, the ShinyHunters extortion gang claimed responsibility for the attack last month and leaked a 33GB archive of files allegedly stolen from the company's systems.

Novocure on ShinyHunters' leak site (BleepingComputer)

ShinyHunters has been previously linked to breaches at more than a dozen Snowflake customers and many third-party integration providers.

The extortion group has also claimed it stole more than 1.5 billion records in Salesloft Drift and Salesforce Aura campaigns targeting hundreds of Salesforce customers.

Most recently, ShinyHunters was linked to breaches at over 100 organizations following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.

The Novocure incident adds to a series of cyberattacks that have affected healthcare companies over the last month, with healthcare software company Unlimited Technology Systems disclosing that a data breach in October 2025 affected more than 3.8 million people, while healthcare IT company CareCloud said that a March data breach has impacted over 3.7 million individuals.

More recently, healthcare services provider Nutex began investigating a data breach involving information theft from company servers, and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident after the ShinyHunters extortion group claimed the theft of 284 million patient data records.

References in this story

  1. Latest Salesloft Drift news www.bleepingcomputer.com The latest news about Salesloft Drift
  2. ShinyHunters claims ongoing Salesforce Aura data theft attacks www.google.com Salesforce is warning customers that hackers are targeting websites with misconfigured Experience Cloud platforms that give guest users access to more data than intended. However, the ShinyHunters extortion gang claims…
  3. Latest Salesforce news www.bleepingcomputer.com The latest news about Salesforce
  4. Oracle mitigates PeopleSoft zero-day exploited in data theft attacks www.bleepingcomputer.com Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.
  5. Unlimited Technology Systems breach impacts 3.8 million people www.bleepingcomputer.com Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.
  6. Healthtech firm CareCloud data breach impacts 3.7 million patients www.bleepingcomputer.com U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals.
  7. Hospital operator Nutex Health says data stolen in cyberattack www.bleepingcomputer.com Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers.
  8. McKesson discloses breach after ShinyHunters claims patient data theft www.bleepingcomputer.com Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming…

← Back to all news