Update, Aug. 23, 2026: Amgen has begun notifying affected patients and confirmed that the stolen files contained more sensitive information than was disclosed in its initial SEC filing.
In consumer notification letters filed with the California Attorney General, Amgen said the compromised data may include names, contact information, dates of birth, government identification numbers, medical information and health insurance information. Certain files also contained Social Security numbers and bank account information.
The breach also affected some children, with potentially exposed information including names, addresses, dates of birth, government identification numbers, medical information and health insurance information.
Amgen is offering affected individuals 24 months of identity monitoring and related protection services. The company has not identified the third-party cloud providers involved or explained how the environments were compromised.
Biotechnology company Amgen has confirmed a cybersecurity incident involving third-party cloud environments that resulted in the theft of proprietary corporate information and patient protected health information (PHI).
The disclosure was made in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), where the company stated it detected unauthorized activity in July 2026 and launched its incident response procedures.
Third-party cloud environments compromised
According to Amgen, its investigation determined that threat actors exfiltrated data stored in multiple cloud environments operated by third-party service providers.
The company initially disclosed that the stolen information included proprietary corporate data, patient protected health information and other information. At the time, investigators were still determining the full scope and sensitivity of the affected files.
Amgen has not disclosed the total number of people affected. Its subsequent patient notification states that 106 Rhode Island residents were impacted, but that figure represents only residents of that state and does not indicate the overall breach population.
Amgen classified the breach as material
Amgen determined on July 29, 2026, that the incident was material after evaluating the volume of files believed to have been affected and the potential sensitivity of the information they contained.
Despite that determination, the company said it did not expect the incident to have a material impact on its financial condition or operating results.
Questions remain over the cloud compromise
Amgen has not attributed the incident to a threat actor or disclosed how the third-party cloud environments were compromised. The company engaged independent cybersecurity forensic experts and said its investigation remains ongoing.
The newly issued patient notifications clarify the types of information stolen, but Amgen has yet to identify the affected cloud providers or disclose the overall number of people impacted.









