Novocure told the SEC on September 1, 2026 that attackers gained unauthorized access to some of its information systems in mid-August, entering through a subsidiary. The oncology device maker, which builds wearable Tumor Treating Fields systems that treat cancer with electrical fields, filed the disclosure as an 8-K under Item 8.01.

The exposed set is narrow but sensitive. Internal company ID numbers for more than 1,400 patients in the United States were taken, with no names attached. Fewer than 50 patients in the western United States had identifying information and general contact details exposed, and the data also held contact information for US healthcare providers plus employee job titles and phone numbers.

The company says the intrusion never reached its medical treatment devices, its ability to operate was not compromised, and all of its systems are fully functional. It contained the access, brought in outside forensic investigators, and expects no material financial impact. No attacker has been named, and nobody has claimed the intrusion.

The filing structure deserves a read from anyone who owns disclosure decisions. Novocure reported under Item 8.01, the voluntary category, and wrote into the filing a commitment to amend under Item 1.05 within four business days if the incident proves material. That keeps the company ahead of the SEC clock without conceding materiality on day one.

Novocure joins Medtronic, Stryker, Abbott, iRhythm, Cook Medical, and Boston Scientific among device makers reporting incidents in 2026. The company employs about 1,300 people and operates from Baar, Switzerland and Portsmouth, New Hampshire. Its notification plans for affected patients depend on what the ongoing forensic investigation finds.

A subsidiary inside the corporate trust boundary is the corporate attack surface, whatever the org chart says. Mapping those connections belongs in the security program long before an incident response retainer gets the call.