NovoCure Limited: NovoCure cyber breach hits 1,400+ patient records

NovoCure Limited: NovoCure cyber breach hits 1,400+ patient records

NovoCure Reports Cybersecurity Incident Affecting Patient and Employee Data

In mid-August 2026, NovoCure Limited, a medical device and oncology therapy company headquartered in Jersey, detected unauthorized access to a portion of its information systems. The company, which trades on the Nasdaq (NVCR), promptly activated its cybersecurity response plan, containing the breach and launching an internal investigation with support from independent forensic experts.

The exposed data included:

  • Internal patient ID numbers for over 1,400 U.S. patient records (no names or direct identifiers were compromised).
  • Additional identifying information for fewer than 50 patients in the western U.S.
  • General contact details for healthcare providers and NovoCure employees, such as job titles and phone numbers.

NovoCure confirmed that no medical treatment devices were accessed, and its operational systems remain fully functional. The company is assessing regulatory and legal notification requirements, including potential disclosures to affected patients.

While the incident is not currently expected to have a material financial impact, NovoCure stated it would file an amended report if further investigation reveals significant risks. The company continues to evaluate the scope and implications of the breach.

Source: https://www.stocktitan.net/sec-filings/NVCR/8-k-novo-cure-ltd-reports-material-event-1bcfd6e39f02.html

Novocure cybersecurity rating report: https://www.rankiteo.com/company/novocure-inc

"id": "NOV1788262208",
"linkid": "novocure-inc",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Over 1,400 U.S. patient records '
                                              '(internal IDs), fewer than 50 '
                                              'patients with additional '
                                              'identifying information, '
                                              'healthcare providers, and '
                                              'employees',
                        'industry': 'Healthcare',
                        'location': 'Jersey',
                        'name': 'NovoCure Limited',
                        'type': 'Medical Device and Oncology Therapy Company'}],
 'data_breach': {'number_of_records_exposed': 'Over 1,400 U.S. patient records '
                                              '(internal IDs), fewer than 50 '
                                              'patients with additional '
                                              'identifying information',
                 'personally_identifiable_information': 'Yes (for fewer than '
                                                        '50 patients)',
                 'sensitivity_of_data': 'Low to moderate (no names or direct '
                                        'identifiers for most records)',
                 'type_of_data_compromised': ['Internal patient ID numbers',
                                              'Additional identifying '
                                              'information',
                                              'General contact details']},
 'date_detected': '2026-08-15',
 'description': 'NovoCure Limited detected unauthorized access to a portion of '
                'its information systems in mid-August 2026. The breach '
                'exposed internal patient ID numbers, additional identifying '
                'information for a small number of patients, and general '
                'contact details for healthcare providers and employees. No '
                'medical treatment devices were accessed, and operational '
                'systems remain fully functional.',
 'impact': {'data_compromised': 'Internal patient ID numbers, additional '
                                'identifying information for fewer than 50 '
                                'patients, general contact details for '
                                'healthcare providers and employees',
            'financial_loss': 'Not currently expected to have a material '
                              'financial impact',
            'legal_liabilities': 'Assessing regulatory and legal notification '
                                 'requirements',
            'operational_impact': 'No operational impact on medical treatment '
                                  'devices or systems',
            'systems_affected': 'Portion of information systems'},
 'investigation_status': 'Ongoing',
 'references': [{'source': 'NovoCure Public Disclosure'}],
 'regulatory_compliance': {'regulatory_notifications': 'Assessing potential '
                                                       'disclosures to '
                                                       'affected patients'},
 'response': {'containment_measures': 'Contained the breach',
              'incident_response_plan_activated': 'Yes',
              'third_party_assistance': 'Independent forensic experts'},
 'title': 'NovoCure Cybersecurity Incident Affecting Patient and Employee Data',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.