Amgen Announces It Suffered a Cloud Data Breach
Pharmaceutical giant Amgen has confirmed a data breach in its third-party cloud systems, resulting in the leak of patient health information and proprietary company data. Details of the attack and the number of affected individuals remain unclear.
What Happened
Amgen, a leading name in the biotechnology and pharmaceutical sectors, has made an announcement that has shaken the cybersecurity world. In an official filing with the Securities and Exchange Commission (SEC), the company reported a significant data breach within multiple cloud systems managed by third-party service providers. The California-based company is known for developing medicines for serious illnesses such as cancer, cardiovascular disease, and rare diseases, a fact that further heightens the sensitivity of the breach.
According to the statement from Amgen, the unauthorized activity was first detected in July 2026. Following this discovery, the company stated it promptly activated its cybersecurity response plan. The initial steps included implementing containment measures to prevent the breach from spreading further. Concurrently, independent forensic experts were hired to conduct an in-depth analysis of the incident's origin, scope, and impact. The task of these experts is to trace the attackers' digital footprints to clarify how they infiltrated the system and what data they accessed.
Preliminary investigations confirmed that the attackers achieved their objectives and stole data from the company's cloud environments. On July 29, 2026, after evaluating the volume of potentially impacted files and the possibility that they contained sensitive information, Amgen decided to classify the incident as "material." Under SEC rules, classifying an event as "material" means it is significant enough to influence an investor's decision, obligating the company to disclose the situation to the public.
Data Exfiltrated
The most critical question for both patients and the company is what data was compromised in the cyberattack. In its Form 8-K filing with the SEC, Amgen explicitly stated that the attackers successfully exfiltrated some data from its cloud environments. The data confirmed to have been leaked includes highly sensitive categories.
Confirmed Leaks:
- Proprietary Data: This category may include the company's trade secrets, research methodologies, formulation details, and other private information that provides a competitive advantage. The exposure of such data to rival firms or malicious actors could pose serious commercial and financial risks for Amgen.
- Protected Health Information (PHI): This constitutes the most alarming aspect of the breach. PHI encompasses patients' identity information, diagnoses, treatment histories, prescription details, and other personal health data. Such data can be used for crimes like identity theft, fraud, and targeted blackmail against patients.
Potential Leaks Still Under Investigation:
Amgen emphasized that the investigation is ongoing and that they are working to determine if additional information was also stolen. Other data types whose status has not yet been clarified include:
- Confidential Business Information: This includes information such as financial reports, strategic plans, and marketing strategies.
- Intellectual Property: Data vital to the company's future, such as patent applications, drug development processes, and clinical trial designs.
- Research and Development (R&D) Data: Clinical trial results, laboratory notes, and scientific discoveries obtained through years of work and billions of dollars in investment.
- Other Patient Information: Other data related to patients that may not fall under the definition of PHI.
The company aims to provide a clearer picture of the full list and scope of the affected data once the investigation is complete.
How the Attack Occurred
Amgen has not yet provided comprehensive technical details about the attack to the public. It is known that the breach occurred not in systems under the company's direct control, but in the environments of third-party cloud providers it uses. This situation may be an example of a supply chain attack, which is becoming increasingly common in the modern business world. As companies move their data and operations to cloud services, the security posture of these service providers becomes an integral part of their own security.
Amgen has not disclosed which cloud providers were affected by this incident or how the attackers infiltrated these environments. It is also not yet clear whether a known threat actor is behind the attack. BleepingComputer, which published the source article, stated that it had posed some specific questions to the company. These included whether the attack was a "vishing" (voice phishing) attack targeting an employee's single sign-on (SSO) account and whether the cybercrime group ShinyHunters had any connection to the incident. However, Amgen has not yet responded to these questions. Therefore, all these possibilities regarding the attack vector remain mere speculation at this time.
Who Is Affected
The primary victims of this data breach are the patients whose health information was exposed. Personal health data is among the most private information, and its misuse can lead to severe emotional and psychological harm beyond financial losses. Amgen has not yet released a figure on how many patients were affected. This number is expected to become clearer as the investigation progresses.
In addition to patients, the company itself, its employees, business partners, and investors are also directly or indirectly affected by the breach. The loss of proprietary data and intellectual property could weaken the company's competitive position in the market. Such incidents also typically damage a company's reputation and can lead to legal proceedings and regulatory fines.
What You Can Do
It is important for patients who have received treatment from Amgen or participated in its clinical trials to take proactive steps at this stage. Although the company will make legally required notifications, it is wise to be vigilant against potential risks:
- Wait for Official Communications: Pay close attention to official notifications from Amgen. The company will inform you if your data has been affected and what you should do. These notifications are usually made by mail or through secure online portals.
- Be Wary of Phishing Attacks: Cybercriminals may use the leaked information to send you targeted phishing emails or smishing (SMS phishing) messages. Be skeptical of messages with subject lines like "Compensation for Amgen data breach victims." Do not trust any message asking for your personal information or passwords.
- Monitor Your Financial Accounts: Regularly check your bank accounts, credit card statements, and credit reports for any suspicious activity.
- Check Your Health Insurance Information: Verify whether you have received notifications from your health insurer for services billed in your name that you did not receive. This could be a sign of medical identity theft.
What the Company Is Saying
Amgen has stated that it is taking the incident seriously and is conducting a comprehensive effort to bring the situation under control. In its SEC filing, the company emphasized that the investigation is ongoing with the help of cybersecurity experts. Amgen has committed to evaluating legal and regulatory notification requirements and will inform affected patients where required by law.
Interestingly, although the company classified the event as "material," it stated that based on current assessments, the breach is "not reasonably likely to materially affect its financial condition or operating results." This statement typically reflects an expectation that legal and remediation costs will not have a major impact on the company's overall financial structure, but the long-term reputational and competitive impacts of the leak remain uncertain. Amgen has indicated it will continue to share updates with the public and regulatory bodies in line with its transparency principles.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.