The global biotechnology company Amgen has disclosed a significant data breach resulting from unauthorized access to cloud environments operated by third-party service providers, leading to the theft of sensitive patient and corporate information. According to a filing with the Securities and Exchange Commission (SEC), the pharmaceutical company, based in California, discovered the incident in July 2026 and initiated its cybersecurity incident response process immediately.
Several containment measures were implemented by the company and independent forensic experts were engaged in an investigation into the breach. As a result of assessing the volume of files that appeared affected and determining that the compromised data could contain sensitive information, Amgen formally classified the incident as material on July 29, 2017.
As part of the legal requirement to inform investors of significant cybersecurity incidents, the company made the disclosure in a regulatory filing with the Securities and Exchange Commission. Upon preliminary investigation, it was determined that hackers successfully exfiltrated data from a number of cloud-based systems.
In addition to proprietary corporate data, protected health information (PHI) belonging to patients, and other sensitive records, this information has been compromised.
Despite not identifying the vendors involved or revealing how the attackers gained access to the stolen data, Amgen claims that the stolen data originated from cloud storage environments managed by third-party service providers. Additionally, Amgen is assessing whether confidential business information, intellectual property, research and development data, and additional patient information was compromised.
During the ongoing forensic investigation, the company is continuing to determine if patient records, confidential business information, intellectual property, research and development data, or other sensitive information was accessed or stolen during the incident.
Upon completion of the forensic investigation, the full scope of the compromise is anticipated.
There has been no disclosure by the company as to identification of the third-party cloud providers, attack vectors used by threat actors, or number of individuals affected. No known cybercriminal organization has been attributed to the incident.
Following an evaluation of the number of potentially affected files and the likelihood that they contained highly sensitive information, Amgen determined that the breach was material on July 29. Even though the breach is serious, the company stated that it does not anticipate that the breach will adversely affect its financial condition or operating results in the near future.
In addition to the assistance of external cybersecurity experts, the investigation is currently ongoing.
Considering its legal and regulatory obligations, Amgen stated that it would notify affected patients where required under applicable data protection laws. According to Amgen's current assessment, the cybersecurity incident has not adversely affected its products, manufacturing operations, financial reporting systems, or its ability to continue supplying medicines and meeting the needs of patients.
There has been an increase in cyberattacks targeting healthcare and pharmaceutical organizations, whose cloud-hosted patient records and valuable research data have made these organizations attractive targets for cybercriminals. In addition to highlighting the increasing cybersecurity risks associated with third-party cloud infrastructure, the incident highlights the importance of securing sensitive healthcare data throughout the supply chain as a whole.
Amgen stated its response was to activate its cybersecurity incident response plan immediately after detecting the unauthorized activity, implement containment measures in order to limit exposure, and continue to work with independent forensic experts to determine the extent and impact of the incident. There has been an increase in cybersecurity incidents impacting the healthcare and pharmaceutical sectors in recent months.
The breach is another in a string of recent cybersecurity incidents.
The industry has also experienced numerous cyber incidents, including Abbott Laboratories, Clover Health, Stryker, Medtronic, Novo Nordisk, and West Pharmaceutical Services, which illustrates the increasing vulnerability of medical and corporate data to cyberattacks.
Amgen has not yet disclosed whether it has received any extortion demands or whether the attackers have attempted to take advantage of the stolen data for ransom or another malicious purpose.
It is anticipated that additional details will be released once the forensic investigation has been completed.
Privacy-preserving technologies are reshaping digital identity verification as governments enforce age verification requirements. It is anticipated that solutions that minimize biometric data collection while maintaining security and regulatory compliance will play an important role in the future of online security.
