Amgen cloud breach exposed patient data, SEC filing reveals

Amgen told the SEC that hackers exfiltrated patient data and proprietary information from its third-party-hosted cloud systems.

MedRisk Staff
By
2 Min Read

Amgen has disclosed a cybersecurity incident that exposed patient data, telling the U.S. Securities and Exchange Commission that hackers broke into third-party-hosted cloud storage and pulled out protected health information along with proprietary business data.

The Thousand Oaks, California biopharmaceutical company said in a Form 8-K filing that it determined in July 2026 that unauthorized parties gained access to certain cloud systems. Amgen activated its cybersecurity response plan, deployed containment measures, and brought in third-party digital forensics experts to assess the nature and scope of the activity.

The investigation confirmed that patients’ protected health information and other data were exfiltrated from the cloud environment, and on July 29 the company determined the incident was material and informed the SEC. Amgen said it does not believe the incident is reasonably likely to affect its financial position, its products, manufacturing operations, financial reporting systems, or its ability to meet patient needs.

The company is still assessing how much patient information, confidential business information, intellectual property, and research and development data was taken, and it has not yet disclosed how the cloud systems were compromised or which threat group was responsible. Amgen said it is determining its regulatory and legal notification requirements, including obligations under HIPAA.

The disclosure adds Amgen to a growing list of pharmaceutical, biotechnology, and medical technology firms hit by cyberattacks in recent months, including Novo Nordisk, Medtronic, Stryker, Abbott Laboratories, West Pharmaceutical Services, and Brainyx AI. Those attacks have been tied to actors including the Iran-linked hacktivist group Handala and the data theft and extortion groups FulcrumSec and ShinyHunters, the latter the subject of a recent Health-ISAC warning to healthcare organizations.

Share This Article