Skip to main content
Emerging ThreatsData Breaches

Amgen Discloses Cloud Data Breach Exposing Patient Health Info

Medical office setting with scattered records and equipment, laptop on desk in foreground.

"The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments," Amgen said in a Form 8‑K filing with the SEC.

July 2026 detection and immediate response

Amgen detected unauthorized activity in July 2026 and activated its cybersecurity response plan, the company said. According to the filing, the firm implemented containment measures and retained independent forensic experts to investigate how attackers gained access to data stored in multiple cloud systems operated by third‑party service providers.

Types of data the company says were taken

Amgen reported that forensic work found sensitive data exfiltrated from cloud environments. The company explicitly named "proprietary data" and "patient protected health information" among the items taken, and said other information was also removed. Amgen is still determining whether additional categories — including confidential business information, intellectual property, research and development data, and other patient information — were accessed or stolen.

Cloud providers, method of compromise, and scope remain unspecified

The company has not disclosed which third‑party cloud providers were involved, how the cloud environments were compromised, or how many people may have been affected. Amgen also said it has not stated whether the attack was linked to any known threat actor. Journalists at BleepingComputer asked Amgen whether the incident involved a vishing attack targeting an employee's single sign‑on account, which cloud services were affected, and whether the company had been contacted or extorted by actors claiming to be ShinyHunters; a response was not immediately available.

Materiality decision, financial assessment, and regulatory notifications

On July 29, Amgen determined the incident was material after evaluating the volume of potentially impacted files and the possibility that they contained sensitive information. Despite that materiality determination, the company said it currently does not believe the incident is reasonably likely to materially affect its financial condition or operating results. Amgen added that it is evaluating legal and regulatory notification requirements and will notify impacted patients where required.

What this means for patients, third‑party cloud providers, and cybersecurity teams

  • Patients: Individuals whose records may have been stored in the affected cloud systems can expect notifications if legal or regulatory requirements apply; Amgen said it will notify impacted patients where required but has not published a scope or timeline.
  • Third‑party cloud providers: Providers named in Amgen’s infrastructure chain — though not yet identified publicly — face new scrutiny over access controls, account protections, and the provenance of exfiltrated files as the company and independent forensic teams continue their work.
  • Cybersecurity and forensic teams: Amgen’s engagement of independent forensic experts and activation of a response plan point to a multi‑discipline effort to contain the incident, trace the intrusion, and catalogue exfiltrated material to meet disclosure obligations.

Amgen’s filing establishes three clear facts: sensitive data was taken from cloud environments, the company has launched an incident response and independent forensics review, and it has judged the breach material while simultaneously concluding it probably will not have a material financial effect. Beyond those points, key operational details remain unresolved — which cloud services were affected, how the attackers moved through those environments, whether confidential R&D and intellectual property were taken, and whether the perpetrators have made contact. The answers to those questions will shape both regulatory obligations and the public’s understanding of the incident as Amgen continues its investigation.

Source: BleepingComputer — Amgen says cloud data breach exposed patient health, proprietary info