AIO APEX

Amgen discloses cloud breach exposing patient health data and proprietary files

BleepingComputer
Share:
Amgen discloses cloud breach exposing patient health data and proprietary files

Amgen, one of the world's largest biotechnology companies, disclosed in a Form 8-K filed with the SEC on July 31, 2026, that hackers exfiltrated patient protected health information and proprietary company data from cloud environments hosted by third-party providers. The filing marks the pharmaceutical maker's first public confirmation of a cybersecurity incident it now classifies as material.

According to the filing, Amgen first detected unauthorized activity across its third-party cloud environments earlier in July. The company activated its cybersecurity response plan, put containment measures in place, and brought in independent forensic experts to investigate. On July 29, after evaluating the volume of files that appeared to be affected and the likelihood that the data involved was sensitive, Amgen determined the incident met the threshold for materiality under SEC disclosure rules — triggering the 8-K filing two days later.

A breach at a company of Amgen's scale carries outsized weight for the healthcare sector. Amgen develops treatments used by millions of patients globally, including therapies for cancer, osteoporosis, and cardiovascular disease, and holds vast repositories of clinical trial data, patient records tied to its drug programs, and proprietary research. Third-party cloud breaches have become one of the most common entry points for attackers targeting large enterprises precisely because they sit outside a company's direct security perimeter while still holding sensitive data — a pattern seen in several major healthcare and pharmaceutical breaches over the past two years.

Amgen has not disclosed which cloud provider or providers were involved, how the environments were initially compromised, how many individuals had their information exposed, or whether the intrusion has been linked to a known threat actor or ransomware group. The company confirmed that exfiltrated data includes proprietary corporate data, patient protected health information (PHI), and other unspecified information, as first reported by BleepingComputer and Reuters.

Despite the scope of the exfiltration, Amgen said it has found no impact to its products, manufacturing operations, or financial reporting systems, and no disruption to its ability to meet patient needs. The company also stated it does not currently believe the incident is reasonably likely to have a material effect on its financial condition or results of operations — a standard disclaimer in breach-related SEC filings that leaves room for the assessment to change as the investigation continues.

The disclosure adds Amgen to a growing list of major healthcare and pharmaceutical companies hit by cloud-based data breaches in 2026, underscoring how attackers are increasingly targeting the third-party infrastructure that stores an organization's most sensitive records rather than attacking corporate networks directly. For patients whose health information may have been exposed, and for the broader biotech sector, the incident is a reminder that data security now extends well beyond a company's own firewall — into every cloud vendor it relies on to store clinical and corporate data.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share:
Amgen discloses cloud breach exposing patient health data and proprietary files | AIO APEX