The ShinyHunters extortion gang has claimed responsibility for a cyberattack on oncology company Novocure, part of a pattern in which the group has repeatedly targeted US healthcare organizations and exposed patient data.

 

What happened

Novocure discovered unauthorized access to some of its information systems in mid-August 2026 and disclosed the incident in a filing with the U.S. Securities and Exchange Commission. An investigation found that attackers accessed over 1,400 U.S. patient records containing ID numbers, though these did not include patient names or other identifying data. For fewer than 50 additional patients in the western US, attackers accessed identifying information along with general contact information for healthcare providers. The breach also exposed contact information for Novocure employees, including job titles and phone numbers. The ShinyHunters extortion gang claimed responsibility for the attack and leaked a 33GB archive of files it says it stole from Novocure's systems. Novocure has not attributed the breach to any group and has not disclosed how attackers gained access.

 

Going deeper

ShinyHunters has a pattern of targeting healthcare organizations through cloud platforms and third-party integrations rather than direct network intrusions. In its attack on pharmaceutical distributor McKesson, the group told reporters it gained access by tricking employees into granting entry through phishing and social engineering, then pulled data from McKesson's cloud-hosted Snowflake and Salesforce environments. ShinyHunters claimed it stole roughly 284 million records from McKesson, though it has acknowledged this figure reflects rows of raw data rather than unique patients, and the group demanded a ransom of over $55 million and gave McKesson 72 hours to respond before publishing the data. Earlier in the year, ShinyHunters attacked dental and vision benefits administrator DentaQuest, an incident that DentaQuest reported to federal regulators as affecting 15 million people, making it the largest health data breach reported so far in 2026. The group has also claimed a breach of medical device maker Baxter International, leaking 7.1 million stolen Salesforce records including personal data after alleging the company would not negotiate.

 

What was said

Novocure stated, "No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional." Also, "The Company takes its obligation to safeguard privacy and security of its patients' data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients."

 

In the know

Novocure develops and commercializes Tumor Treating Fields (TTFields), a non-invasive electromagnetic field therapy used to treat cancer tumors, and employs more than 1,300 people across North America, Europe, the Middle East, and Asia. ShinyHunters is a financially motivated extortion gang that has focused on stealing data from cloud platforms like Salesforce and Snowflake, often through phishing and social engineering aimed at employees, rather than exploiting software vulnerabilities directly.

 

Why it matters

This attack shows ShinyHunters is willing to go after even specialized, smaller-scale healthcare providers like Novocure, not just distributors like McKesson. That matters because it signals no part of the healthcare supply chain is too niche to be a target, from cancer therapy device makers to dental benefit administrators to pharmaceutical distributors. The consistency of the group's method, gaining access through cloud platforms and third-party applications rather than the target's systems, means healthcare organizations can't treat this as a one-off incident to patch and move past. It points to weak points across the industry, that is, the vendor and cloud integrations that sit outside a hospital's or company's direct control.

 

The bottom line

Novocure's breach is smaller in scale than ShinyHunters' recent hits on McKesson or DentaQuest, but it has the same pattern. Healthcare organizations should treat every third-party cloud application and vendor integration as a potential entry point, since ShinyHunters has repeatedly shown it doesn't need to breach a company's own network to access patient data.

 

FAQs

What is ShinyHunters?

ShinyHunters is a financially motivated data-extortion group known for breaching organizations, stealing large volumes of data, and threatening to leak it unless a ransom is paid.

 

How can healthcare companies protect themselves from these kinds of attacks?

Healthcare companies can reduce risk by securing third-party and cloud application access, training employees to recognize phishing and social engineering attempts, and limiting how much data vendors can access at once.

 

Are companies required to report data breaches like this?

Yes, U.S. companies handling health data are required to notify affected individuals and regulators within specific timeframes under laws like HIPAA.

 

Does paying a ransom guarantee stolen data won't be leaked?

No, paying a ransom does not guarantee attackers will delete the data or refrain from leaking or reselling it later.