Amgen Discloses Cloud Breach, Patient Data Compromised
Biotechnology giant **Amgen** has revealed a data breach stemming from unauthorized activity within its third-party cloud environments. The incident, detected in July, resulted in the exfiltration of proprietary company data and sensitive patient health information, underscoring the persistent supply chain risks in the healthcare sector.
California-based biotechnology company **Amgen** has confirmed that patient information and proprietary company data were stolen from cloud systems operated by its third-party providers.
In a recent filing with the **Securities and Exchange Commission (SEC)**, the company stated it detected unauthorized activity in July involving data stored in cloud environments hosted by external service providers.
The subsequent investigation uncovered that attackers successfully exfiltrated company information, including proprietary data, patients' protected health information, and other sensitive records.
**Amgen** has indicated that, at present, the incident has not disrupted its products, manufacturing operations, financial reporting systems, or its ability to supply medicines to patients. The company also noted that the breach is "not reasonably likely to have a material impact on the company's financial condition or results of operations."
The investigation is ongoing, with **Amgen** still assessing the full scope of the breach, including whether additional confidential business information, intellectual property, or research and development data was accessed or stolen. The company plans to notify affected patients.
Details surrounding the attack remain scarce. **Amgen** has not disclosed how the attackers gained access to the cloud environments, identified the specific affected cloud providers, or attributed the intrusion to any particular threat actor. There is currently no public indication of ransomware involvement, and no cybercriminal group has claimed responsibility for the breach.
**Amgen**, with a market capitalization of $207.8 billion, is a global leader in biotechnology, known for products such as **Prolia** and **Xgeva** for osteoporosis, and cancer treatments like **Kyprolis** and **Lumakras**.
The healthcare industry continues to be a prime target for cyberattacks from both nation-state actors and cybercriminals. This incident follows other significant breaches in the sector:
* In May, Pennsylvania-based **West Pharmaceutical Services** reported a ransomware attack that disrupted manufacturing, shipping, and receiving systems after data exfiltration and network encryption.
* In August 2025 (sic), Indiana-based drug research company **Inotiv** disclosed a ransomware attack that forced the shutdown of critical systems, with the **Qilin** ransomware gang later claiming responsibility.
