Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
Amgen is a California-based biotechnology company that develops and manufactures medicines for serious illnesses, including cancer, cardiovascular disease, inflammation, and rare diseases.
The company said it detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident.
The investigation found that the attackers stole sensitive data from the cloud environments.
"The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments," Amgen said in a Form 8-K filing with the SEC.
The company is still determining whether additional information was accessed or stolen, including confidential business information, intellectual property, research and development data, and other patient information.
Amgen has not disclosed which third-party cloud providers were involved, how the environments were compromised, how many people may have been affected, or whether the attack was linked to a known threat actor.
On July 29, the company determined that the incident was material after evaluating the volume of potentially impacted files and the possibility that they contained sensitive information.
However, Amgen currently does not believe the incident is reasonably likely to materially affect its financial condition or operating results.
The company said it is continuing to investigate the breach with the assistance of third-party cybersecurity experts.
... continue reading