Pharmaceutical Giant Amgen Discloses Data Breach Affecting Corporate and Patient Data
Biotechnology firm **Amgen** has revealed a data breach stemming from unauthorized access to corporate and patient information stored across multiple third-party cloud systems. The incident, detected in July 2026, led to the exfiltration of sensitive data, prompting a comprehensive cybersecurity response and ongoing investigation.
California-based biotechnology company **Amgen**, a key player in developing medicines for serious illnesses, has confirmed a significant data breach impacting its cloud infrastructure.
The company detected unauthorized activity in July 2026 and swiftly initiated its cybersecurity incident response plan. This included implementing containment measures and engaging independent forensic experts to investigate the scope of the compromise.
The investigation has since confirmed that threat actors successfully exfiltrated sensitive data from the affected cloud environments. In a **Form 8-K** filing with the **SEC**, **Amgen** stated, "The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments."
Details remain scarce regarding the specific third-party cloud providers involved, the methods of compromise, or the number of individuals potentially affected. **Amgen** has also not linked the attack to any known threat actor group.
The company is still working to determine the full extent of the accessed or stolen information, which could include confidential business information, intellectual property, research and development data, and additional patient information.
On July 29, the incident was deemed material by **Amgen** following an evaluation of the volume of potentially impacted files and the sensitive nature of their contents. However, the company currently does not anticipate a material impact on its financial condition or operating results.
**Amgen** continues its investigation with the assistance of external cybersecurity experts. The company is also assessing its legal and regulatory notification requirements and has committed to informing affected patients where mandated.