Techtimes
Amgen Data Breach Exposes Patient PHI via Third-Party Cloud Vendors
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Amgen disclosed a data breach affecting patient protected health information (PHI) and proprietary data stored in third-party cloud environments. The breach was detected in July 2026, with attackers exploiting vulnerabilities in vendor systems, likely through vishing attacks targeting single sign-on accounts. Amgen confirmed the incident in a Form 8-K filed with the SEC on July 31, 2026, indicating that the breach did not impact its operational systems but compromised sensitive patient data. The company is currently assessing the full extent of the breach and has activated its cybersecurity response plan, including hiring forensic experts for investigation. The timeline for notifying affected individuals under HIPAA is uncertain as it may depend on when the vendor detected the intrusion.
Key Points: • Amgen's patient PHI was stolen through third-party cloud vendors, not directly from its systems. • The breach was disclosed on July 31, 2026, with a potential HIPAA notification timeline already in progress. • Attackers likely used vishing to compromise single sign-on accounts, allowing data exfiltration.