Amgen says a breach of multiple third-party cloud environments exposed patient health information and company data. In an SEC filing, the drugmaker said it detected unauthorized activity in July 2026 and later confirmed data exfiltration, meaning files were stolen, including proprietary information and patient protected health information. The company has not named the cloud providers, attack method, victim count, or any threat actor.
Why it matters: This affects patients and partners as well as a major healthcare company’s research and business data. Organizations that share or store sensitive data with cloud providers should review third-party access and monitoring, while potentially affected patients should watch for breach notifications and related phishing.
SecurityWeek News
2026.08.07
94% relevant
This article restates and slightly contextualizes the same Amgen incident, noting unauthorized July 2026 access to third-party cloud environments and exfiltration of proprietary data and protected health information.
2026.08.03
99% relevant
This article is a direct report on the same disclosed breach, adding that Amgen detected the unauthorized activity in July, said there was no identified disruption to manufacturing or medicine supply, and noted it is still assessing exposure of intellectual property and research data.
Lawrence Abrams
2026.07.31
100% relevant
This article appears to be the first material disclosure establishing Amgen's July 2026 cloud-data breach as a distinct incident involving stolen patient and proprietary information.
← Back to all stories