Techtimes Amgen Data Breach Exposes Patient PHI via Third-Party Cloud Vendors
Article Content
- •Amgen's patient PHI was stolen through third-party cloud vendors, not directly from its systems.
- •The breach was disclosed on July 31, 2026, with a potential HIPAA notification timeline already in progress.
- •Attackers likely used vishing to compromise single sign-on accounts, allowing data exfiltration.
Amgen disclosed a data breach affecting patient protected health information (PHI) and proprietary data stored in third-party cloud environments. The breach was detected in July 2026, with attackers exploiting vulnerabilities in vendor systems, likely through vishing attacks targeting single sign-on accounts. Amgen confirmed the incident in a Form 8-K filed with the SEC on July 31, 2026, indicating that the breach did not impact its operational systems but compromised sensitive patient data. The company is currently assessing the full extent of the breach and has activated its cybersecurity response plan, including hiring forensic experts for investigation. The timeline for notifying affected individuals under HIPAA is uncertain as it may depend on when the vendor detected the intrusion.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Scattered Spider and AbbVie in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Knight Office Phishing Kit Targets Microsoft 365 Accounts via Session Hijacking A new phishing kit named 'Knight Office' has been identified, targeting Microsoft 365 accounts by stealing active login sessions instead of passwords. Discovered by Huntress during an investigation of suspicious sign-in activity in August 2026, the kit uses a sophisticated dashboard to manage victims and harvested…