Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical giant Amgen has announced a significant data breach that exposes sensitive information, including patient health records and proprietary corporate data. The breach occurred in multiple cloud systems operated by third-party service providers, with threat actors successfully exfiltrating large volumes of data.

Amgen, a California-based biotechnology company, develops and manufactures medicines for serious illnesses such as cancer, cardiovascular disease, and rare diseases. In July 2026, the company detected unauthorized activity in its cloud environments and triggered its cybersecurity response plan. An investigation was launched, with independent forensic experts hired to investigate the incident.

The findings revealed that sensitive data had been stolen from the cloud environments. Amgen’s Form 8-K filing with the SEC states that “some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments.” The company is still determining the full extent of the breach, which may include confidential business information, intellectual property, research and development data, and additional patient information.

Amgen has not disclosed which third-party cloud providers were involved or how the environments were compromised. It also remains unclear whether the attack was linked to a known threat actor, such as ShinyHunters, who have been responsible for several high-profile healthcare data breaches in recent months. The company’s statement indicates that it is still assessing the potential impact on its financial condition and operating results.

While Amgen currently believes the breach will not significantly affect its operations or finances, the incident highlights the ongoing threat of cloud-based attacks. As more organizations move their data to cloud services, they also increase their attack surface. Cloud security is a complex issue, with multiple layers of protection required to prevent unauthorized access.

The Amgen breach serves as a reminder for healthcare and pharmaceutical companies to prioritize cloud security and protect sensitive patient information. Organizations must ensure that their cloud providers are taking adequate measures to secure data, including regular audits, vulnerability assessments, and incident response planning. Additionally, employees handling sensitive data must be trained on best practices for cloud security and aware of the risks associated with unauthorized access.

As the investigation continues, Amgen will need to evaluate its notification requirements under various regulations, such as HIPAA, and inform affected patients where necessary. For other organizations, this breach serves as a warning to test their cloud security posture regularly, using tools such as breach and attack simulation (BAS) testing to identify vulnerabilities before attackers do.


Source: Bleeping Computer — 2026-07-31