Amgen Data Breach Exposes Patient PHI via Third-Party Cloud Vendors

Amgen Data Breach Exposes Patient PHI via Third-Party Cloud Vendors

First seen 2 Aug 2026, 08:52 UTC BleepingcomputerTechtimesbellatorcyber.comPharma.Economictimes.IndiatimesBiospace+2 88% similarity 65.2

Article Content

Browse articles
ThreatCluster

Amgen disclosed a data breach affecting patient protected health information (PHI) and proprietary data stored in third-party cloud environments. The breach was detected in July 2026, with attackers exploiting vulnerabilities in vendor systems, likely through vishing attacks targeting single sign-on accounts. Amgen confirmed the incident in a Form 8-K filed with the SEC on July 31, 2026, indicating that the breach did not impact its operational systems but compromised sensitive patient data. The company is currently assessing the full extent of the breach and has activated its cybersecurity response plan, including hiring forensic experts for investigation. The timeline for notifying affected individuals under HIPAA is uncertain as it may depend on when the vendor detected the intrusion.

Key Points: • Amgen's patient PHI was stolen through third-party cloud vendors, not directly from its systems. • The breach was disclosed on July 31, 2026, with a potential HIPAA notification timeline already in progress. • Attackers likely used vishing to compromise single sign-on accounts, allowing data exfiltration.

ThreatCluster AI How this analysis works

Timeline

2026-07-24
Health-ISAC issued advisory on increased attacks
Health-ISAC warned of a rise in attacks by ShinyHunters against healthcare organizations, detailing their attack methods.
Techtimes
2026-07-29
Amgen determines breach is material
Amgen assessed the volume of impacted files and confirmed the breach's materiality, triggering SEC disclosure requirements.
Bleepingcomputer
2026-07-31
Amgen files Form 8-K with SEC
Amgen disclosed the data breach in a Form 8-K, confirming the exfiltration of sensitive patient data from third-party vendors.
Techtimes
2026-08-01
Amgen activates cybersecurity response plan
Following the breach detection, Amgen implemented containment measures and engaged forensic experts to investigate the incident.
Bleepingcomputer
2026-08-02
Amgen continues assessing breach impact
Amgen is evaluating the extent of data accessed or stolen, including patient and proprietary information, following the breach.
Pharma.Economictimes.Indiatimes

Community

Browse all →