Breach taxonomy
Summary
In mid-August 2026, NovoCure became aware, through a subsidiary, of unauthorized access to some of its information systems. Forensic review found the exposed data included internal patient ID numbers for over 1,400 U.S. patient records (no names or other identifiers), additional identifying information for fewer than 50 patients in the western U.S., and general contact information for healthcare providers and employees. No medical treatment devices were accessed, and all systems remained fully functional. The company activated its cybersecurity response plan, implemented containment measures and is evaluating patient notification requirements. Filed under Item 8.01; materiality not yet determined as of the filing date.
Tagging rationale
ThreatUnknown
Filing does not attribute the unauthorized access to any actor category -> UNKNOWN.
MethodsData Exfil
Filing reports 'unauthorized access to some of its information systems' with forensic experts 'reviewing the exposed data that was accessed'; no ransomware, outage or misconfiguration is described -> DATA-EXFIL.
AssetsPersonal Data
Filing states the exposed data included internal patient ID numbers for 'over 1,400 U.S. patient records', identifying information for 'fewer than 50 other patients', and contact information for providers and employees -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Filing discloses exposure of patient, provider and employee data while stating 'our ability to operate has not been compromised' -> INFO-PRIVACY-LOSS.
Business continuityNot Required
Filing states 'our ability to operate has not been compromised and all of our systems are fully functional', so continuity procedures were not required -> Not Required.
Impact
Exposure was limited to internal-only patient ID numbers for ~1,400 records, identifying data for fewer than 50 patients and business contact details, with no device access and no operational impact -> score 1.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 8.01 Other Events. In mid-August 2026, NovoCure Limited (the "Company," "we," or "us") through a subsidiary, became aware of unauthorized access to some of its information systems. Upon detecting the unauthorized access, the Company activated its cybersecurity response plan, implemented containment measures, and initiated an internal investigation of the event. The Company also engaged independent cybersecurity forensic experts to assist with the investigation, including reviewing the exposed data that was accessed. Based on the investigation to date, the Company determined that the exposed data included: internal Company patient ID numbers for over 1,400 U.S. patient records (these ID numbers are only used internally and no patient names or other identifying data for these was exposed); patient data for fewer than 50 other patients in the western U.S. that included additional identifying information; general contact information for healthcare providers we work with; and general contact information for Novocure employees, such as their job titles and phone numbers. No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional. The Company takes its obligation to safeguard privacy and security of its patients' data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients. At this time, we do not believe that this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations; however, at the time of this filing we are continuing to ascertain additional information regarding this incident. If additional information is obtained whereby we determine this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations, we undertake to file an amendment to this Form 8-K filing under Item 1.05 containing such information within four business days after we, without unreasonable delay, determine such information, or within four business days after such information becomes available.