Amgen Confirms Major Data Breach Affecting Patient Health Records and Corporate Files

The biotechnology company detected the compromise in July and engaged external forensic specialists to investigate the full scope of the breach.

3 dk okuma 7 görüntülenme
what is a data breach

Biotechnology company Amgen revealed a significant cybersecurity breach involving unauthorized access to patient protected health information and proprietary business records. The incident originated within third-party cloud storage environments used by the California-based drugmaker, and the company formally classified the breach as material on July 29 following initial detection in July.

İçindekiler

How the Breach Was Discovered and Contained

Amgen identified suspicious unauthorized activity across its third-party cloud environments during July. Upon recognition of the compromise, the company activated its enterprise cybersecurity incident response framework to isolate affected systems and prevent further unauthorized access. The drugmaker retained independent external forensic cybersecurity specialists to conduct a comprehensive investigation into the technical entry vectors used by threat actors and determine the complete volume of exfiltrated data.

According to the company's Securities and Exchange Commission Form 8-K filing, the stolen files contain a combination of proprietary business records, patient health details, and other confidential internal information. The investigation remains ongoing as forensic teams work to assess the full sensitivity and scope of the compromised records. Amgen implemented additional technical security enhancements to protect surrounding digital infrastructure from further compromise.

Operational Impact and Business Continuity

Despite the exfiltration of sensitive patient and corporate data, Amgen confirmed that the incident has not disrupted its primary commercial or clinical operations. The company stated that it has identified no operational impact on drug manufacturing capabilities, core product supply lines, or financial reporting systems. The drugmaker reassured healthcare partners and investors that its ability to deliver essential medicines and fulfill clinical needs remains unaffected by the security breach.

The incident highlights growing digital threats targeting life sciences corporations, where interconnected cloud infrastructure and vendor ecosystems present lucrative targets for cybercriminal syndicates. Amgen's disclosure underscores the persistent risks associated with third-party cloud environments and the importance of robust security protocols within interconnected business networks.

What is a data breach?+
A data breach occurs when unauthorized third parties gain access to sensitive or confidential information stored by an organization. This can include personal health records, financial data, corporate files, or other protected information. Breaches typically result from security vulnerabilities, compromised credentials, or targeted cyberattacks and can lead to identity theft, financial loss, or regulatory consequences.
How did the threat actors access Amgen's cloud systems?+
The specific technical entry vectors used by threat actors have not yet been disclosed. Amgen stated that the breach originated within third-party cloud storage environments, and the company engaged external forensic specialists to investigate how the systems were compromised. The investigation remains ongoing to determine whether specific databases or cloud accounts were targeted.
What types of data were stolen in the Amgen breach?+
According to Amgen's SEC filing, the exfiltrated data includes patient protected health information, proprietary business records, and other confidential internal information. The company's forensic investigation continues to assess the full sensitivity and volume of the compromised files.
Has the breach affected Amgen's ability to produce and deliver medicines?+
No. Amgen confirmed that the cybersecurity incident has not disrupted its primary commercial or clinical operations, drug manufacturing capabilities, core product supply lines, or financial reporting systems. The company stated its ability to deliver essential medicines and fulfill clinical needs remains unaffected.
Why are healthcare companies vulnerable to cloud-based breaches?+
Healthcare and life sciences organizations often rely on interconnected cloud infrastructure and vendor ecosystems to manage large volumes of sensitive patient data and research files. These third-party environments can present security vulnerabilities if not properly secured, making them lucrative targets for cybercriminal syndicates seeking to steal proprietary information or personal health records.

Bülten Aboneliği

Haftada bir, teknoloji ve dijital dünyadan seçtiklerimiz e-postanda. Spam yok, sadece içerik.

Benzer Haberler

Yorumlar

0
Henüz yorum yok. İlk yorumu sen yap!
app store'da indir