Amgen Patients' Data Stolen Through Third-Party Vendors
The pharmaceutical giant Amgen recently disclosed that its patient protected health information (PHI) was stolen by threat actors, but the breach did not come from within the company's systems. Instead, it occurred through third-party cloud vendors trusted to hold sensitive data.
According to a Form 8-K filed with the SEC on July 31, 2026, Amgen confirmed that attackers exfiltrated proprietary data and PHI from multiple cloud environments managed by outside service providers. The company's systems, drugs, and supply chain remain intact, but its patients' data is now in the wrong hands.
The HIPAA breach notification rules require Amgen to notify affected individuals within 60 days of discovering the incident, potentially dating back to when the vendor detected the intrusion. Under the SEC's 2023 cybersecurity disclosure rule, Amgen was required to file within four business days of determining the incident was material.
Amgen has not confirmed whether ShinyHunters, a threat group known for targeting major organizations, was involved in the breach. However, health-ISAC issued an advisory warning that ShinyHunters had successfully attacked healthcare and medical technology organizations using a specific attack chain involving vishing (voice social engineering) and single sign-on account takeover.