Amgen Hit by Data Exfiltration Hack Involving Patient Records and Trade Secrets
Amgen has notified the U.S. Securities and Exchange Commission (SEC) about a data exfiltration hack that potentially exposed sensitive company information, including patient health records and trade secrets.
The California-based biotechnology firm reported nearly $37 billion in revenue in fiscal 2025 and said it detected unauthorized activity in July involving data stored in cloud environments hosted by third-party providers. Amgen implemented containment measures and engaged external cybersecurity forensic experts after discovering the breach.
The company stated that some of its data, including proprietary information and patient protected health information, has been exfiltrated from these cloud environments, but no cybercrime gang has yet surfaced to claim involvement in the Amgen data theft. The hack bears similarities to recent attacks carried out against other healthcare and biotech companies by prolific threat group ShinyHunters.
Eric Bordeau, virtual CIO at managed services and cybersecurity firm Logically, noted that 'these companies aren't just holding patient information. They also have research, intellectual property, financial information and years of research and development invested in their products.' He added that the value lies not only in selling stolen data but also in the pressure it puts on organizations once it's been compromised.