Amgen, the California-based biotechnology company known for developing treatments for cancer, cardiovascular disease, and rare illnesses, has disclosed a data breach involving multiple cloud environments managed by third-party service providers.

In a Form 8-K filing with the Securities and Exchange Commission, Amgen said it detected unauthorized activity in July 2026 and immediately activated its cybersecurity incident response plan. The company implemented containment measures and brought in independent forensic experts to investigate the scope of the intrusion.

The investigation confirmed that attackers exfiltrated sensitive data from the affected cloud systems. According to the filing, the stolen data includes proprietary corporate information and patient protected health information (PHI). Amgen said it is still working to determine whether additional categories of data were accessed or stolen, including confidential business information, intellectual property, research and development records, and further patient data.

The company has not named the third-party cloud providers involved, disclosed how the environments were compromised, or estimated how many individuals may be affected. Amgen also has not confirmed whether the incident is linked to any known threat actor group.

Material Incident, Limited Financial Impact Expected

Amgen determined on July 29 that the breach qualified as a material incident, based on the volume of potentially affected files and the likelihood that they contained sensitive information. Despite this determination, the company stated it does not currently believe the incident is reasonably likely to have a material effect on its financial condition or operating results.

Amgen said it continues to investigate the breach with the help of third-party cybersecurity experts and is evaluating its legal and regulatory notification obligations. The company confirmed it will notify affected patients where required by law.

Unanswered Questions

BleepingComputer reached out to Amgen to ask whether the breach stemmed from a vishing attack targeting an employee’s single sign-on credentials, which specific cloud services were compromised, and whether the company has been contacted by or extorted by threat actors associated with the ShinyHunters group. Amgen had not responded at the time of reporting.

The disclosure follows a string of recent breaches at healthcare and pharmaceutical organizations tied to cloud environment compromises, including incidents at West Pharmaceutical, Medtronic, and medical billing firm MCBS, amid broader warnings from health sector information sharing groups about escalating data theft campaigns targeting the industry.