Intelligence
highSupply ChainActive

Amgen cloud breach exposes PHI and proprietary data in third-party environments

Amgen disclosed that attackers exfiltrated proprietary data, patient protected health information and other information from multiple cloud environments operated by third-party providers. The attack vector and responsible actor remain unknown.

S
Sebastion

Affected

AmgenThird-party cloud service providers

Amgen disclosed that threat actors exfiltrated data from multiple cloud environments operated by third-party service providers. The confirmed material includes proprietary data, patient protected health information and other information. Amgen was still assessing whether confidential business information, intellectual property, research and development data, or further patient information had also been accessed or stolen.

The attack vector remains unknown. Amgen had not identified the affected providers, the number of people affected or a responsible threat actor at source time. BleepingComputer asked whether investigators were examining a vishing attack against an employee's single sign-on account and possible contact or extortion by actors claiming to be ShinyHunters, but Amgen had not responded. That possible ShinyHunters, vishing and SSO angle was being investigated, not confirmed.

Amgen detected the unauthorised activity in July 2026, activated its cyber security response plan, introduced containment measures and retained independent forensic experts. On 29 July, it determined that the incident was material after considering the volume of potentially affected files and the possibility that they contained sensitive information.

The company reported the incident in a Form 8-K filed with the US Securities and Exchange Commission. It said the incident was not currently reasonably likely to have a material effect on its financial condition or operating results. Its investigation and assessment of legal and regulatory notification requirements remained in progress, with affected patients to be notified where required.