Amgen says attackers stole patient health information and proprietary data from third-party cloud systems

Amgen says a breach of multiple third-party cloud environments exposed patient health information and company data. In an SEC filing, the drugmaker said it detected unauthorized activity in July 2026 and later confirmed data exfiltration, meaning files were stolen, including proprietary information and patient protected health information. The company has not named the cloud providers, attack method, victim count, or any threat actor.
Why it matters: This affects patients and partners as well as a major healthcare company’s research and business data. Organizations that share or store sensitive data with cloud providers should review third-party access and monitoring, while potentially affected patients should watch for breach notifications and related phishing.

Sources

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
SecurityWeek News 2026.08.07 94% relevant
This article restates and slightly contextualizes the same Amgen incident, noting unauthorized July 2026 access to third-party cloud environments and exfiltration of proprietary data and protected health information.
Biotech giant Amgen says patient data stolen from third-party cloud systems
2026.08.03 99% relevant
This article is a direct report on the same disclosed breach, adding that Amgen detected the unauthorized activity in July, said there was no identified disruption to manufacturing or medicine supply, and noted it is still assessing exposure of intellectual property and research data.
Amgen says cloud data breach exposed patient health, proprietary info
Lawrence Abrams 2026.07.31 100% relevant
This article appears to be the first material disclosure establishing Amgen's July 2026 cloud-data breach as a distinct incident involving stolen patient and proprietary information.
← Back to all stories