Drugmaker Amgen disclosed on July 31 that hackers stole company data and patient health information in a cybersecurity incident involving cloud storage systems run by third-party providers. The company determined the breach was material on July 29 after evaluating the number of affected files and the potential sensitivity of the data.
What Happened
Amgen detected unauthorized access to its cloud storage infrastructure in July 2026. The breach involved systems operated by third-party cloud providers, not Amgen’s own servers directly. The company activated its cybersecurity response plan, implemented containment measures, and brought in independent forensic experts to investigate the scope.
In a regulatory filing, Amgen stated it was “assessing whether and/or the extent to which patient, confidential business information, intellectual property, research and development, or other information may have been accessed or stolen.”
What Data Was Compromised
The confirmed compromised data includes:
- Patient health information (PHI)
- Company data
- Potentially confidential business information
- Intellectual property and research and development data
Amgen has not yet specified the exact number of affected individuals or the full range of data types exposed. The company said it is evaluating what regulatory and legal notifications are required and will notify affected parties, including patients, based on its findings.
Why Healthcare Data Breaches Keep Happening
Healthcare data is among the most valuable on the dark web because it contains complete identity profiles: names, dates of birth, medical history, insurance information, and Social Security numbers. Third-party cloud storage adds another layer of risk because healthcare companies rely on external providers for data hosting while retaining legal responsibility for that data.
The Amgen breach follows a pattern of healthcare companies disclosing incidents involving cloud infrastructure managed by external vendors. When a breach happens at a third-party provider, the affected company often discovers it weeks or months later, giving attackers more time to exfiltrate data.
What Amgen Is Doing
The company has engaged independent forensic cybersecurity experts to conduct a full investigation. Amgen said it “takes the obligation to protect patient privacy and data security very seriously” and is working to determine the complete scope of affected data. Notifications to patients and regulators will follow the investigation’s findings.
Amgen Data Breach FAQ
What data was stolen in the Amgen breach?
Patient health information, company data, and potentially intellectual property and R&D information from third-party cloud storage systems.
When did Amgen discover the breach?
The company determined the incident was material on July 29, 2026, and publicly disclosed it on July 31.
Were Amgen’s own servers hacked?
No, the breach involved cloud storage systems operated by third-party providers, not Amgen’s internal infrastructure directly.
How many patients are affected?
Amgen has not yet specified the exact number. The investigation is ongoing.
What should Amgen patients do?
Monitor your health insurance statements and credit reports. Amgen will notify affected individuals directly once the investigation is complete.
