Amgen Says Attackers Stole Patient Data From Third-Party Cloud Systems
The biotech giant disclosed the breach in an SEC filing after detecting unauthorized activity in July, but has not named the cloud providers involved or how many patients are affected.

Key points
- Amgen, a California biotechnology company, told the SEC on July 29 that attackers stole patient health data and proprietary information from cloud systems run by outside vendors.
- The intrusion was detected in July 2026, and Amgen says the stolen files include "patient protected health information" and internal company data.
- Amgen has not named the cloud providers, the attack method, or how many people were affected.
- The company says it does not currently expect the breach to materially hurt its financial results.
- Investigators are still checking whether research data, intellectual property, and additional patient records were also taken.
Amgen, one of the largest pharmaceutical companies in the United States, says criminals broke into cloud storage systems run by its outside vendors and stole patient health records along with confidential business data.
The company, based in Thousand Oaks, California, makes medicines for cancer, heart disease, inflammation, and rare conditions. It disclosed the breach in a Form 8-K filing with the SEC, the formal notice public companies must file when something significant happens.
Amgen detected the intrusion in July 2026. On July 29 it decided the incident was serious enough to count as "material," a legal term meaning big enough that investors need to know.
What was stolen?
Patient health information and proprietary corporate data, according to Amgen's filing. The company is still working out exactly what else the attackers took.
In its filing, Amgen said "some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments." Exfiltrated is the industry word for copied out and taken away.
Investigators are also checking whether the attackers grabbed:
- Confidential business information
- Intellectual property and research and development data
- Additional patient records beyond what has already been confirmed
Amgen has not said how many patients are affected. It has promised to notify people directly where the law requires it.
How did the attackers get in?
Amgen has not said. The company has not named the cloud providers involved, has not described the attack method, and has not linked the intrusion to any known criminal group.
BleepingComputer, which first reported the disclosure, asked Amgen whether the break-in started with a vishing call (a phone scam where criminals impersonate IT staff to trick an employee into handing over login details) targeting an employee's single sign-on account. Single sign-on is the one master login that gives staff access to many company systems at once, which makes it a prized target. The outlet also asked whether the extortion group known as ShinyHunters had contacted Amgen. The company did not immediately respond.
Those questions are not idle. A string of recent attacks on large firms has followed the same pattern: a phone call, a stolen login, and a mass download from cloud platforms the victim did not realise were so exposed.
Should patients be worried?
Cautious, not panicked. Amgen has said patient protected health information was taken, but has not yet told individual patients what specifically was in the files. Anyone who has been an Amgen clinical trial participant or received Amgen patient support services should watch for a notification letter in the coming weeks.
In the meantime, treat unexpected emails or phone calls claiming to be from Amgen with suspicion. Do not click links in messages asking you to "verify" health information. Go directly to the company's official website if you need to check something.
| Detail | What Amgen has said |
|---|---|
| Breach detected | July 2026 |
| Declared material | July 29, 2026 |
| Data confirmed stolen | Patient health information, proprietary data |
| Cloud providers named | None |
| Patients notified | To follow, where legally required |
| Financial impact expected | Not material, per company |
Amgen says it activated its incident response plan, brought in outside forensic investigators, and is working with legal advisors on notification requirements in the United States and abroad. The investigation is ongoing.



