Amgen Says Attackers Stole Patient Data From Third-Party Cloud Systems

The biotech giant disclosed the breach in an SEC filing after detecting unauthorized activity in July, but has not named the cloud providers involved or how many patients are affected.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a laboratory glass vial containing a coiled DNA double helix model, sitting on a dark reflective surfa
Share

Key points

  • Amgen, a California biotechnology company, told the SEC on July 29 that attackers stole patient health data and proprietary information from cloud systems run by outside vendors.
  • The intrusion was detected in July 2026, and Amgen says the stolen files include "patient protected health information" and internal company data.
  • Amgen has not named the cloud providers, the attack method, or how many people were affected.
  • The company says it does not currently expect the breach to materially hurt its financial results.
  • Investigators are still checking whether intellectual property, research data, and other patient records were also taken.

Amgen, one of the largest pharmaceutical companies in the United States, says criminals broke into cloud storage systems run by its outside vendors and stole patient health records along with confidential business data.

The company, based in Thousand Oaks, California, makes medicines for cancer and cardiovascular disease, inflammation, and rare conditions. It disclosed the breach in a Form 8-K filing with the SEC, the formal notice public companies must file when something significant happens.

Amgen detected the intrusion in July 2026. On July 29 it decided the incident was serious enough to count as "material," a legal term meaning big enough that investors need to know. This is the same disclosure mechanism we saw a day earlier when Analog Devices reported its June breach, and it's becoming a reliable leading indicator that stolen data is already circulating.

What was stolen?

Patient health information and proprietary corporate data, according to Amgen's filing. The company is still working out exactly what else the attackers took.

In its filing, Amgen said "some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments." Exfiltrated means copied out and removed.

Investigators are also checking whether the attackers grabbed confidential business information, intellectual property, R&D data, and additional patient records beyond what's already confirmed.

Amgen hasn't said how many patients are affected. It's promised to notify people directly where the law requires it.

How did the attackers get in?

Amgen hasn't said. The company has not named the cloud providers involved, described the attack method, or linked the intrusion to any known criminal group.

BleepingComputer, which first reported the disclosure, asked Amgen whether the break-in started with a vishing call, a phone scam where criminals impersonate IT staff to trick an employee into surrendering login credentials, targeting a single sign-on account. Single sign-on is a master login that grants access to many company systems at once, which makes it a prized target. BleepingComputer also asked whether the extortion group ShinyHunters had contacted Amgen. No response was available.

Those questions aren't idle. Recent attacks on large firms have followed a recognisable pattern: one stolen credential, one cloud platform, and a mass download the victim didn't know was possible.

Should patients be worried?

Cautious, not panicked. Amgen has confirmed patient protected health information was taken but hasn't told individuals what specifically was in the files. Anyone who has been an Amgen clinical trial participant or received Amgen patient support services should watch for a notification letter in the coming weeks.

Treat unexpected calls or emails claiming to be from Amgen with suspicion. Don't click links in messages asking you to verify health information. Go directly to the company's official website if you need to check anything.

Detail What Amgen has said
Breach detected July 2026
Declared material July 29, 2026
Data confirmed stolen Patient health information, proprietary data
Cloud providers named None
Patients notified To follow, where legally required
Financial impact expected Not material, per company

Amgen says it activated its incident response plan, brought in outside forensic investigators, and is working with legal advisors on notification requirements in the United States and abroad. The investigation is ongoing.

The part that should concern security teams most isn't what Amgen has disclosed. It's everything the company still can't confirm six weeks after detecting the intrusion.

© 2026 Threat Vectr