Skip to content
Data breachContained

Amgen discloses material cloud data breach exposing patient and proprietary data (2026)

Biotech giant Amgen disclosed in a July 2026 SEC filing a material cybersecurity incident in which attackers exfiltrated patient health information and proprietary data from third-party cloud environments.

Victim
Amgen

On 29 July 2026, Amgen β€” one of the world's largest biotechnology companies β€” disclosed in a filing with the U.S. Securities and Exchange Commission that it had suffered a material cybersecurity incident in which attackers exfiltrated data, including patient protected health information and proprietary company information, from cloud environments operated by third-party providers.

What happened

Amgen said it had identified the unauthorized activity earlier in July and responded by activating its cybersecurity incident-response plan, putting containment measures in place and engaging independent forensic experts. The compromised data resided in cloud environments run by third-party providers rather than on Amgen's core internal systems, once again highlighting the risk that third-party and cloud infrastructure poses to even the best-resourced enterprises.

The company confirmed that some of its data β€” including proprietary data, patient protected health information, and other information β€” had been exfiltrated, and said its investigation into whether additional confidential business data, intellectual property, or research-and-development material was accessed remained ongoing.

Impact and response

Amgen stated that, as of disclosure, it had not identified any impact to its products, manufacturing operations, financial reporting, or delivery of medicines to patients. Nevertheless, under U.S. securities rules the company judged the incident material β€” a determination it reached on 29 July β€” and reported it accordingly. Given the exposure of patient health information, the breach also carries notification obligations under U.S. health-privacy law.

Why it matters

For a company whose value is anchored in patient data and closely guarded research, the theft of protected health information and proprietary material is a serious event even without operational disruption. Amgen's disclosure is part of a broader 2026 pattern in which attackers increasingly bypass hardened corporate networks by targeting the third-party cloud platforms that large enterprises rely on to store and process sensitive data.

Timeline

  1. Amgen identifies unauthorized activity in cloud environments run by third-party providers and activates its cybersecurity response plan.

  2. Amgen determines the incident is material and discloses it in an SEC Form 8-K, confirming that patient health information and proprietary data were exfiltrated.

Sources

  1. sec.govhttps://www.sec.gov/Archives/edgar/data/0000318154/000031815426000119/amgn-20260729.htm
  2. fiercepharma.comhttps://www.fiercepharma.com/pharma/amgen-says-patient-health-data-ip-stolen-cybersecurity-breach
  3. hipaajournal.comhttps://www.hipaajournal.com/amgen-cyberattack-data-breach/
  4. claimsjournal.comhttps://www.claimsjournal.com/news/national/2026/08/04/339271.htm

Related incidents