Amgen Hacked: Patient Data, IP Potentially Stolen
Biotech firm Amgen has notified US regulators about a data exfiltration hack that may have exposed patient information and intellectual property. The company, which reported nearly $37 billion in revenue in fiscal 2025, said it detected unauthorized activity in July involving data stored in cloud environments hosted by third-party providers.
Amgen's filing with the SEC states that the company has since learned some of its data, including proprietary information and patient protected health information, has been exfiltrated from these cloud environments. The incident is deemed 'material' due to the volume of files potentially compromised and the types of information contained.
The hack bears similarities to recent attacks on healthcare companies by the ShinyHunters gang, which has carried out a wave of cloud-scale data exfiltration in the sector. Experts say that while the cloud is not inherently less secure, successful attacks can have a broader impact due to data storage practices.