Amgen Discloses Cybersecurity Breach Exposing Patient Data
In July 2026, Amgen Inc., a leading biopharmaceutical company, disclosed a cybersecurity incident involving unauthorized access to third-party-hosted cloud storage systems. The breach resulted in the exfiltration of proprietary data, protected health information (PHI) of patients, and other sensitive information.
Amgen promptly activated its cybersecurity response plan, engaged third-party digital forensics experts, and notified the U.S. Securities and Exchange Commission (SEC) of the material nature of the incident on July 29, 2026. As of the latest public disclosures, the specific attack vector and threat actor remain unidentified.
The company's internal security monitoring identified anomalous activity, prompting the activation of its incident response plan. Immediate containment measures were implemented, and external digital forensics experts were engaged to support the investigation and remediation efforts.