Biotechnology company Amgen has confirmed a cybersecurity incident involving third-party cloud environments that resulted in the theft of proprietary corporate information and patient protected health information (PHI).
The disclosure was made in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), where the company stated it detected unauthorized activity in July 2026 and launched its incident response procedures. Amgen said it has engaged independent cybersecurity experts to investigate the breach and determine its full scope.
Third-party cloud environments compromised
According to Amgen, its investigation determined that threat actors exfiltrated data stored in multiple cloud environments operated by third-party service providers.
The company said the stolen information includes proprietary corporate data, patient protected health information, and other information. Investigators are continuing to determine whether confidential business information, intellectual property, research and development data, or additional patient information was also affected.
Amgen has not disclosed which cloud providers were involved, how the environments were compromised, or how many individuals may have been impacted.
Material incident disclosed to regulators
Amgen determined on July 29, 2026, that the incident was material after evaluating the volume of files believed to have been affected and the potential sensitivity of the information they contained.
Despite that determination, the company said it does not currently expect the incident to have a material impact on its financial condition or operating results. The investigation remains ongoing, and Amgen said it is evaluating its legal and regulatory notification obligations before notifying affected individuals where required.
Investigation ongoing
Amgen has not attributed the incident to any threat actor or disclosed how the third-party cloud environments were compromised. The company said it is continuing to investigate the breach with the assistance of independent cybersecurity experts while assessing legal and regulatory notification requirements.
The company also said it will notify affected individuals where required as additional information becomes available. BreachNews will update this article if Amgen releases further technical details, identifies the affected cloud providers, or provides additional information regarding the scope of the breach.












