Amgen Confirms Cloud Data Breach Exposed Patient Health and Proprietary Information

Amgen disclosed a material cloud data breach after attackers stole patient protected health information and proprietary corporate data from third-party cloud environments.
BreachNews featured image for Amgen showing the company's logo over a dark blue digital background representing a cybersecurity incident involving cloud-hosted data.

Biotechnology company Amgen has confirmed a cybersecurity incident involving third-party cloud environments that resulted in the theft of proprietary corporate information and patient protected health information (PHI).

The disclosure was made in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), where the company stated it detected unauthorized activity in July 2026 and launched its incident response procedures. Amgen said it has engaged independent cybersecurity experts to investigate the breach and determine its full scope.

Third-party cloud environments compromised

According to Amgen, its investigation determined that threat actors exfiltrated data stored in multiple cloud environments operated by third-party service providers.

The company said the stolen information includes proprietary corporate data, patient protected health information, and other information. Investigators are continuing to determine whether confidential business information, intellectual property, research and development data, or additional patient information was also affected.

Amgen has not disclosed which cloud providers were involved, how the environments were compromised, or how many individuals may have been impacted.

Material incident disclosed to regulators

Amgen determined on July 29, 2026, that the incident was material after evaluating the volume of files believed to have been affected and the potential sensitivity of the information they contained.

Despite that determination, the company said it does not currently expect the incident to have a material impact on its financial condition or operating results. The investigation remains ongoing, and Amgen said it is evaluating its legal and regulatory notification obligations before notifying affected individuals where required.

Investigation ongoing

Amgen has not attributed the incident to any threat actor or disclosed how the third-party cloud environments were compromised. The company said it is continuing to investigate the breach with the assistance of independent cybersecurity experts while assessing legal and regulatory notification requirements.

The company also said it will notify affected individuals where required as additional information becomes available. BreachNews will update this article if Amgen releases further technical details, identifies the affected cloud providers, or provides additional information regarding the scope of the breach.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site