Incident tracker

Recent cyber attacks and data breaches

DisclosedCompanyWhat happenedTypeRecordsSource
2026-09-01NovoCure LtdNVCR

Surgical & Medical Instruments & Apparatus

NovoCure Ltd disclosed a cybersecurity incident

In mid-August 2026, NovoCure Limited (the "Company," "we," or "us") through a subsidiary, became aware of unauthorized access to some of its information systems. Upon detecting the unauthorized access, the Company activated its cybersecurity response plan, implemented containment measures, and initiated an internal investigation of the event. The Company also engaged independent cybersecurity forensic experts to assist with the investigation, including reviewing the exposed data that was accessed. Based on the investigation to date, the Company determined that the exposed data included: internal Company patient ID numbers for over 1,400 U.S. patient records (these ID numbers are only used internally and no patient names or other identifying data for these was exposed); patient data for fewer than 50 other patients in the western U.S. that included additional identifying information; general contact information for healthcare providers we work with; and general contact information for Novocure employees, such as their job titles and phone numbers. No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional. The Company takes its obligation to safeguard privacy and security of its patients' data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients. At this time, we do not believe that this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations; however, at the time of this filing we are continuing to ascertain additional information regarding this incident. If additional information is obtained whereby we determine this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations, we undertake to file an amendment to this Form 8-K filing under Item 1.05 containing such information within four business days after we, without unreasonable delay, determine such information, or within four business days after such information becomes available. Forward-Looking Statements In addition to historical facts or statements of current condition, this press release may contain forward-looking statements. Forward-looking statements provide Novocure's current expectations or forecasts of future events. These may include statements regarding anticipated scientific progress on its research programs, clinical study progress, development of potential products, interpretation of clinical results, prospects for regulatory approval, manufacturing development and capabilities, market prospects for its products, coverage, collections from third-party payers and other statements regarding matters that are not historical facts. You may identify some of these forward-looking statements by the use of words in the statements such as "anticipate," "estimate," "expect," "project," "intend," "plan," "believe" or other words and terms of similar meaning. Novocure's performance and financial results could differ materially from those reflected in these forward-looking statements due to general financial, economic, environmental, regulatory and political conditions and other more specific risks and uncertainties facing Novocure such as those set forth in its Annual Report on Form 10-K filed on February 26, 2026, and subsequent flings with the U.S. Securities and Exchange Commission. Given these risks and uncertainties, any or all of these forward-looking statements may prove to be incorrect. Therefore, you should not rely on any such factors or forward-looking statements. Furthermore, Novocure does not intend to update publicly any forward-looking statement, except as required by law. Any forward-looking statements herein speak only as of the date hereof. T

Regulatory filing
Not disclosedSEC EDGAR
2026-09-01Park Dental Partners, Inc.PARK

Services-Misc Health & Allied Services, NEC

Park Dental Partners, Inc. disclosed a material cybersecurity incident
Regulatory filing
Not disclosedSEC EDGAR
2026-08-31Virta Health Corp. and Virta Medical, PCVirta Health Corp. and Virta Medical, PC: a data breach

Virta Health Corp. and Virta Medical, PC notified the California Attorney General of a data breach on August 31, 2026, with the breach dated March 19, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-31Berkeley Research Group, LLCBerkeley Research Group, LLC: a data breach

Berkeley Research Group, LLC notified the California Attorney General of a data breach on August 31, 2026, with the breach dated February 28, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-31Nutex Health Inc.NUTX

Services-Business Services, NEC

Nutex Health Inc. disclosed a material cybersecurity incident
Regulatory filing
Not disclosedSEC EDGAR
2026-08-29Vista Del Mar Child and Family Services

Healthcare

Vista Del Mar Child and Family Services: a health data breach

Vista Del Mar Child and Family Services, a healthcare provider in CA, reported a breach of health information affecting 500 people to the US Department of Health and Human Services on August 29, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
500HHS Office for Civil Rights
2026-08-28Bennett CollegeBennett College: a data breach

Bennett College notified the California Attorney General of a data breach on August 28, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-28RB American Group LLCRB American Group LLC: a data breach

RB American Group LLC notified the Washington State Attorney General on August 28, 2026 of a data breach that occurred on April 8, 2026, affecting 974 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Unique Private Key (e.g. used to authenticate or sign an electronic record), Student ID Number, Military ID Number, Passport Number, Health Insurance Policy or ID Number, Medical Information, Biometric Data.

Data breach
Not disclosedWashington State Attorney General
2026-08-27Integrated Specialty Coverages, LLC (“ISC”)Integrated Specialty Coverages, LLC (“ISC”): a data breach

Integrated Specialty Coverages, LLC (“ISC”) notified the California Attorney General of a data breach on August 27, 2026, with the breach dated June 8, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-27AnMed Health

Healthcare

AnMed Health: a health data breach

AnMed Health, a healthcare provider in SC, reported a breach of health information affecting 501 people to the US Department of Health and Human Services on August 27, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
501HHS Office for Civil Rights

About this tracker

435
Incidents
287
Ransomware gang claims
722
Last 30 days
389
Companies tracked
2,742,501,669
Records disclosed