Amgen Discloses Cloud Data Breach Exposing Patient Health Records
Pharmaceutical giant Amgen discloses a significant data breach after threat actors steal sensitive information from cloud environments operated by third-party service providers. The California-based biotechnology company, which develops medicines for cancer, cardiovascular disease, and rare illnesses, detects the unauthorized activity in July 2026 and activates its cybersecurity response plan. Amgen hires independent forensic experts to investigate the incident and implement containment measures.
The investigation reveals that attackers exfiltrate proprietary data, patient protected health information, and other sensitive details from the compromised cloud systems. Amgen files a Form 8-K with the SEC and determines the incident is material based on the volume of potentially impacted files. The company continues assessing whether additional confidential business information, intellectual property, or research and development data is also accessed or stolen.
Amgen does not disclose which third-party cloud providers are involved, how many individuals are affected, or whether a known threat actor is responsible. The company states the breach is unlikely to materially impact its financial condition or operating results. Amgen says it is evaluating legal and regulatory notification requirements and plans to notify impacted patients where legally required.