Cyber Incident Victim: Amgen
Timeline
Summary
Amgen reported that hackers gained unauthorized access to its cloud environment hosted by external service providers and exfiltrated patient health information and proprietary intellectual property. The company activated its cybersecurity response plan, contained the activity, and a forensic investigation confirmed the data theft. The company stated that it has not observed any impact on its products, manufacturing, financial reporting, or patient deliveries, and while the breach is considered material, it does not expect a material effect on its financial condition or results of operations. It plans to notify affected individuals. The incident adds to a series of cybersecurity attacks on biopharma firms, including recent breaches at Novo Nordisk and Novartis, and occurs amid growing concerns about AI‑enabled threats, prompting the company to maintain an AI Government Council and a dedicated cybersecurity and digital trust team.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In July, Amgen identified unauthorized activity in its cloud storage systems hosted by external service providers. The company activated its cybersecurity response plan and initiated containment measures. A subsequent forensic investigation confirmed that attackers had stolen sensitive patient health information and proprietary company data. The breach was disclosed in a securities filing on Friday, August 3, 2026.

Amgen stated that it has not identified any impact to its products, manufacturing operations, financial reporting or delivery to patients to date. It has determined that the incident is "material." The company added that the breach is "not reasonably likely to have a material impact on the Company's financial condition or results of operations." Although its investigation into the full scope of compromised confidential records remains ongoing. Amgen said it plans to notify affected patients.
Amgen’s latest encounter adds to a growing series of cybersecurity incidents within the biopharma sector, which often holds high-value intellectual property and sensitive patient records. The company has also established an AI Government Council comprised of cross-functional leadership that oversees the company’s adoption of third-party AI services. More broadly, a cybersecurity and digital trust team is responsible for cybersecurity at Amgen.
