Pharmaceutical giant Amgen has suffered a significant cloud-based data breach, exposing sensitive patient health information and proprietary corporate data to unauthorized access. The incident highlights the ongoing risks of cloud storage vulnerabilities and the importance of robust cybersecurity measures.
Amgen, based in California, is a leading developer and manufacturer of medicines for serious illnesses, including cancer and cardiovascular disease. According to the company’s recent filing with the Securities and Exchange Commission (SEC), threat actors stole sensitive data from multiple cloud environments operated by third-party service providers. The breach was detected in July 2026, prompting Amgen to activate its cybersecurity response plan and engage independent forensic experts to investigate.
The investigation revealed that attackers had exfiltrated proprietary data, patient protected health information, and other confidential information from the cloud environments. Amgen is still determining whether additional sensitive data, including intellectual property, research and development data, and patient information, was accessed or stolen. While the company has not disclosed which specific third-party cloud providers were involved or how the environments were compromised, it has confirmed that the breach does not appear to have had a significant financial impact on its operations.
This incident is particularly concerning given the sensitive nature of the data involved. Amgen’s patients may be at risk of identity theft and other forms of exploitation, while the company itself faces reputational damage and potential regulatory scrutiny. The breach also underscores the importance of robust cybersecurity measures for cloud-based storage, which is increasingly relied upon by organizations across various industries.
Amgen has stated that it will continue to investigate the breach with the assistance of third-party cybersecurity experts and evaluate its notification requirements under relevant laws and regulations. Impacted patients will be notified where required, but the company’s current assessment suggests that the incident is not reasonably likely to materially affect its financial condition or operating results.
This incident serves as a reminder for organizations to regularly test their cloud storage environments and ensure that they have robust security measures in place. With more companies moving sensitive data to the cloud, it’s essential to prioritize cybersecurity and take proactive steps to prevent such breaches from occurring. By doing so, organizations can minimize the risk of sensitive data being exposed and protect their customers’ trust.
In light of this incident, we urge our readers to remain vigilant and review their own cloud storage security protocols. Regularly testing your environment against potential threats can help identify vulnerabilities before they are exploited by attackers. Consider implementing breach and attack simulation tests to validate your SIEM and EDR rules, ensuring that your security measures can detect and respond effectively to emerging threats.
Source: Bleeping Computer — 2026-07-31