Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
Intelligence analysis by Llama

Amgen detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident.
Imagine you have a big box of important papers, and someone breaks into your house and steals the box. That's kind of what happened to Amgen, a company that makes medicines. They had some important information stored in a cloud, like a big computer storage unit, and someone broke in and stole it. This is a big deal because it could have some people's personal health information in it.
Analysis
A $60B Vote of Confidence
Amgen, a California-based biotechnology company, has suffered a significant data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. The company detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident. The investigation found that the attackers stole sensitive data from the cloud environments.
Why Cursor?
The company is still determining whether additional information was accessed or stolen, including confidential business information, intellectual property, research and development data, and other patient information. Amgen has not disclosed which third-party cloud providers were involved, how the environments were compromised, how many people may have been affected, or whether the attack was linked to a known threat actor. On July 29, the company determined that the incident was material after evaluating the volume of potentially impacted files and the possibility that they contained sensitive information.
The Road Ahead
Amgen is continuing to investigate the breach with the assistance of third-party cybersecurity experts. The company is evaluating legal and regulatory notification requirements and will notify impacted patients where required. BleepingComputer contacted Amgen to ask whether the breach involved a vishing attack targeting an employee's single sign-on account, which cloud services were affected, and whether the company has been contacted or extorted by threat actors claiming to be ShinyHunters. A response was not immediately available.
Key points
- Amgen suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
- The company detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident.
- Amgen is still determining whether additional information was accessed or stolen, including confidential business information, intellectual property, research and development data, and other patient information.
- The company is continuing to investigate the breach with the assistance of third-party cybersecurity experts and will notify impacted patients where required.
Amgen is taking steps to investigate the breach and notify impacted patients, which is a positive step towards transparency and accountability. Additionally, the company's decision to hire independent forensic experts to investigate the incident demonstrates a commitment to understanding the scope of the breach and preventing future incidents.
The breach highlights the ongoing threat of cyber attacks and the importance of robust cybersecurity measures in protecting sensitive patient information and proprietary data. If Amgen's cloud providers were not secure, it raises concerns about the security of other companies' cloud environments and the potential for similar breaches.


