Amgen
Incident posture
Timeline
Summary
A leading California-based biopharmaceutical company disclosed a cybersecurity incident involving unauthorized access to cloud storage systems hosted by third-party service providers, resulting in the exfiltration of proprietary business data, patient protected health information, and other sensitive records. The company detected the unauthorized activity and activated its cybersecurity response plan, deploying containment measures and engaging external digital forensics experts to investigate the scope of the breach. The investigation confirmed that data had been stolen from the cloud environments, and the company determined the incident to be material, subsequently notifying the U.S. Securities and Exchange Commission via a Form 8-K filing. No impact has been identified to the company's products, manufacturing operations, financial reporting systems, or its ability to deliver medicines to patients, and no ransomware activity or threat actor attribution has been publicly reported. Notification to affected patients is planned as the assessment of compromised information continues.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In July 2026, Amgen Inc., a California-based multinational biopharmaceutical company headquartered in Thousand Oaks, identified unauthorized activity involving data stored in cloud environments hosted by third-party service providers. The company activated its cybersecurity response plan, initiated containment measures, and engaged external digital forensics experts to investigate the nature and scope of the incident. The forensic investigation subsequently confirmed that attackers had exfiltrated proprietary company data, patients' protected health information, and other sensitive information from the cloud systems. Specific details regarding the cloud provider or providers involved, the method of initial access, the techniques used for lateral movement, and the technical means of data exfiltration have not been publicly disclosed. No technical indicators of compromise, malware hashes, or command-and-control infrastructure have been released.
On July 29, 2026, Amgen concluded that the incident was material due to the volume of files believed to have been involved and the potential sensitivity of the exfiltrated information. The company then informed the U.S. Securities and Exchange Commission and filed a Form 8-K disclosure. The filing, made on July 31, 2026, stated that the incident is not reasonably likely to have a material impact on Amgen's financial condition or results of operations. Amgen also stated that it had not identified any impact to its products, manufacturing operations, financial reporting systems, or its ability to meet patient needs as a result of the breach. There is no public indication that ransomware was deployed in the attack, and no cybercriminal group has claimed responsibility for the intrusion. Attribution to any specific threat actor remains uncertain, as no direct technical evidence has been made public.
As of the public disclosures available in early August 2026, Amgen continues to assess the full scope of the compromised data, including whether confidential business information, intellectual property, research and development data, or additional patient information was accessed or stolen. The company has stated its intention to notify affected patients and is in the process of determining the applicable regulatory and legal notification requirements, including its responsibilities under the Health Insurance Portability and Accountability Act. The exact number of individuals impacted has not been disclosed. Amgen has not yet directly notified impacted individuals, a delay that has drawn the attention of plaintiff law firms including Edelson Lechtzin LLP and Schubert Jonckheer & Kolbe, both of which have announced investigations into potential class action claims arising from the breach. The incident is part of a broader pattern of cybersecurity events affecting the pharmaceutical, biotechnology, and medical device sectors, following recent breaches at companies such as Novo Nordisk, Medtronic, Stryker, Abbott Laboratories, and West Pharmaceutical Services.
Sources
Sources available to members: 6 sources.