Amgen disclosed a material data breach involving cloud environments operated by third-party service providers, saying attackers gained unauthorized access and exfiltrated patient protected health information, proprietary company data, and other records. The company detected the activity in July 2026, activated its incident response plan, contained the intrusion, and brought in independent forensic experts to investigate. Amgen said it has not yet identified the affected cloud providers, the intrusion method, the number of impacted individuals, or any threat actor tied to the breach.
The company determined the incident was material on July 29 based on the volume of affected files and the possibility that highly sensitive information was included. Amgen is still assessing whether confidential business information, intellectual property, research and development data, or additional patient data were accessed, while also evaluating notification obligations tied to the theft of PHI. Reporting on the incident indicates the breach could trigger both HIPAA compliance requirements and SEC disclosure scrutiny, although Amgen said it does not currently expect a material impact on its financial condition or operations.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Amgen determined on July 29, 2026 that the incident was material after reviewing the volume of impacted files and the possibility that sensitive information was included. The company said attackers exfiltrated protected health information, proprietary data, and other records.
Amgen said it detected unauthorized activity in July 2026 affecting cloud environments operated by third-party service providers. After discovery, the company activated its cybersecurity response plan, contained the incident, and engaged independent forensic experts.
Amgen disclosed a cloud-related data breach involving third-party service provider environments that exposed patient health information and proprietary company data. The company said it was still assessing whether additional confidential business information, intellectual property, research and development data, or more patient data were also accessed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecysecurity.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.