Techtimes
Amgen Data Breach Exposes Patient PHI via Third-Party Cloud Vendors
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Amgen reported a data breach involving the theft of patient protected health information (PHI) and proprietary data from third-party cloud vendors. The breach was disclosed in a Form 8-K filed with the SEC on July 31, 2026, after Amgen determined the incident was material on July 29. The attackers exploited vulnerabilities in the cloud environments, likely using vishing to gain access to employee accounts. Amgen's internal systems remained unaffected, but sensitive data has been exfiltrated. The company is investigating the breach with external cybersecurity experts and evaluating legal notification requirements. Specific details about the cloud vendors involved and the number of affected individuals have not been disclosed. Amgen is also assessing whether additional sensitive information was accessed during the breach.
Key Points: • Amgen's patient PHI was stolen through third-party cloud vendors, not its own systems. • The breach was linked to a vishing attack that compromised employee accounts via SSO. • Amgen is actively investigating the incident and has engaged independent forensic experts.