
Amgen, one of the world’s largest biotechnology companies, has disclosed a data breach through an SEC Form 8-K filing after attackers stole sensitive data from cloud systems operated by third-party service providers. The company said it detected the unauthorized access in July 2026, activated its cybersecurity response plan, and brought in independent forensic experts to investigate. What those experts found was significant: threat actors had successfully exfiltrated patient protected health information, proprietary research and development data, and other corporate data from multiple cloud environments.
Amgen has not disclosed which cloud providers were involved, how attackers initially gained access, or how many patients may be affected. The company said it is still working to determine whether additional data — including confidential business information, intellectual property, and further patient records — was accessed. Amgen determined the incident was material on July 29, 2026, based on the volume of files potentially exposed, though the company said it does not currently expect the breach to materially affect its financial results. Amgen said it is evaluating legal and regulatory notification requirements and will notify affected patients where required by law.
