Incident
Published 2026-09-01
Verified 2026-09-19

Novocure Form 8-K: mid-August intrusion; 1,400+ U.S. patient ID numbers accessed

NovoCure Limited's Form 8-K dated 1 September 2026 (Item 8.01) says that in mid-August 2026 a subsidiary became aware of unauthorised access to some information systems. The company activated its cybersecurity response plan, contained the event, and engaged independent forensic experts. Exposed data to date: internal company patient ID numbers for over 1,400 U.S. patient records (IDs used only internally; no names or other identifying data for those records); identifying information for fewer than 50 other patients in the western U.S.; general contact information for healthcare providers; and employee contact details such as job titles and phone numbers. Novocure states no access to medical treatment devices was obtained, operations were not compromised, and systems remain fully functional. It does not currently expect a material financial impact and says it will make required notifications, including to impacted patients. Vector and threat actor are not named in the filing.

Product
Novocure information systems
Exploited in Australia?
unknown

Primary: NovoCure Form 8-K (1 Sep 2026) · Vendor: SEC EDGAR (NVCR) · BleepingComputer (1 Sep 2026)

breaches