Amgen Confirms Data Breach Involving Patient Information and Corporate Records
AI-generated from multiple sources. Verify before acting on this reporting.
THOUSAND OAKS, Calif. — Amgen Inc., the California-based biotechnology company, confirmed on July 31 that unauthorized actors stole corporate data and patient information from multiple cloud systems operated by third-party service providers.
The pharmaceutical giant disclosed the incident after detecting suspicious activity within its digital infrastructure in early July 2026. The breach involved the exfiltration of sensitive records stored across external cloud environments managed by vendors supporting Amgen's operations. While the company has not specified the exact number of individuals affected, it stated that both proprietary corporate data and personal health information were compromised.
Amgen immediately launched an investigation in coordination with cybersecurity experts to determine the full scope of the intrusion. The company reported that no evidence suggests any unauthorized use or sale of the stolen data at this time. However, officials noted that threat actors gained access to systems through vulnerabilities exploited within third-party cloud configurations, a method increasingly common in attacks targeting large healthcare organizations.
The compromised patient information reportedly includes names and dates of birth for individuals who received care from Amgen-sponsored clinical trials or services. The company emphasized that sensitive data such as Social Security numbers and financial account details were not part of the exfiltration, though it cautioned that some records may contain medical history relevant to ongoing treatments.
In response to the breach, Amgen has initiated a comprehensive review of its vendor management protocols and is implementing additional security controls across all cloud-based systems. The company notified federal law enforcement agencies regarding the incident and began reaching out to affected individuals directly to offer credit monitoring services and identity theft protection resources for at least 12 months.
Regulatory bodies, including state attorneys general in jurisdictions where Amgen operates clinical trials, have been informed of the breach as part of mandatory disclosure requirements. The Securities and Exchange Commission has also received notice of the incident given its potential impact on corporate governance and investor relations.
Amgen stated that it is committed to protecting patient privacy and maintaining trust with stakeholders while working diligently to secure its digital assets. The company expects the investigation to continue over the coming weeks as forensic analysts trace the movement of stolen data across global networks.
Questions remain regarding how long threat actors maintained access before detection and whether similar vulnerabilities exist in other third-party systems used by Amgen or competing biotechnology firms. Industry observers are watching closely for further developments, particularly if additional breaches emerge from related cloud providers serving the healthcare sector.