BigTech CompaniesBusinessCybersecurityNewswire

Amgen cloud breach exposes patient health, proprietary data

Originally published on: August 2, 2026
▼ Summary

– Amgen disclosed a data breach involving theft of corporate data and patient protected health information from cloud systems operated by third-party service providers.
– The unauthorized activity was detected in July 2026, prompting Amgen to activate its cybersecurity response plan and hire independent forensic experts.
– The company has not revealed which cloud providers were involved, how the compromise occurred, the number of affected individuals, or any link to a known threat actor.
– On July 29, Amgen determined the incident was material based on the volume of potentially impacted files, but it does not expect a material effect on its financial condition.
– Amgen is assessing legal and regulatory notification requirements and will notify impacted patients where required; BleepingComputer’s questions about a possible vishing attack or ShinyHunters involvement remain unanswered.

Amgen, the California-based biotechnology firm known for developing treatments for cancer, cardiovascular conditions, inflammation, and rare diseases, has confirmed a data breach involving the theft of corporate files and patient health information from cloud environments operated by external vendors.

The company detected unauthorized access in July 2026 and immediately activated its cybersecurity response plan. Containment protocols were implemented, and independent forensic experts were brought in to assess the scope of the intrusion.

According to the investigation, attackers successfully exfiltrated sensitive material from these third-party cloud systems. In a filing with the U. S. Securities and Exchange Commission, Amgen stated that stolen data includes proprietary company information, patient protected health information, and additional records.

The company has not yet confirmed whether other categories of data were compromised, such as intellectual property, confidential business documents, research and development files, or further patient details.

Amgen has withheld key details about the incident, including which cloud service providers were targeted, the method of compromise, the number of affected individuals, and whether a known threat actor is responsible.

On July 29, Amgen determined the breach was material after reviewing the volume of potentially exposed files and the likelihood that they contained sensitive information. Despite that classification, the company does not currently expect the incident to have a reasonable likelihood of materially impacting its financial condition or operating results.

The investigation remains ongoing with support from third-party cybersecurity specialists. Amgen also stated it is reviewing legal and regulatory notification obligations and will contact affected patients as required.

BleepingComputer reached out to Amgen for additional details, including whether the breach stemmed from a vishing attack on an employee’s single sign-on credentials, which specific cloud services were involved, and whether the company has been contacted or threatened by actors claiming to be ShinyHunters. No response was available at the time of publication.

(Source: BleepingComputer)

Topics

data breach 98% cloud security 93% healthcare data privacy 91% incident response 88% sec filings 86% biotech industry 84% cyber threat actors 82% intellectual property theft 81% materiality assessment 78% legal compliance 76%