ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Amgen discloses data breach involving patient health information stored in third-party cloud systems

Amgen, a California-based biotechnology company that develops and manufactures treatments for cancer, cardiovascular disease, inflammation and rare diseases, disclosed that hackers stole company data and patient health information from cloud storage systems operated by outside vendors. The company detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, putting containment measures in place and bringing in independent forensic experts to investigate.


In a Form 8-K filing with the Securities and Exchange Commission, Amgen said its investigation determined that attackers had extracted data from the affected cloud environments. The company stated, "The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments."


Amgen said it is still working to determine whether additional material was accessed or taken, including confidential business records, intellectual property, research and development data and further patient information. The company has not named the third-party cloud providers involved, explained how the systems were breached, estimated how many individuals may be affected, or said whether the intrusion has been tied to a known threat actor.


On July 29, Amgen concluded that the breach qualified as a material incident after weighing the number of files that appeared to be affected and the likelihood that those files held sensitive information. Despite that determination, the company said it does not currently believe the breach is reasonably likely to have a material effect on its financial condition or operating results. Amgen also said it has so far found no impact on its products, manufacturing operations, financial reporting systems or its capacity to meet patient needs.


The company said its investigation is continuing with support from outside cybersecurity specialists, and that it is reviewing what legal and regulatory notification obligations apply, with plans to notify affected patients where required.


The disclosure places Amgen among a growing list of health care and pharmaceutical companies reporting cyberattacks in recent months, a group that has also included Abbott Laboratories, Clover Health, Stryker, Medtronic, Novo Nordisk and West Pharmaceutical Services.


The breach becomes public as Amgen separately faces scrutiny over its rare-disease drug Tavneos, after a major medical journal retracted a key study supporting the treatment and regulators in the United States and Europe moved to seek its removal from the market.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543