Amgen Confirms Major Data Breach Affecting Patient Health Records and Corporate Files
The biotechnology company detected the compromise in July and engaged external forensic specialists to investigate the full scope of the breach.

Biotechnology company Amgen revealed a significant cybersecurity breach involving unauthorized access to patient protected health information and proprietary business records. The incident originated within third-party cloud storage environments used by the California-based drugmaker, and the company formally classified the breach as material on July 29 following initial detection in July.
How the Breach Was Discovered and Contained
Amgen identified suspicious unauthorized activity across its third-party cloud environments during July. Upon recognition of the compromise, the company activated its enterprise cybersecurity incident response framework to isolate affected systems and prevent further unauthorized access. The drugmaker retained independent external forensic cybersecurity specialists to conduct a comprehensive investigation into the technical entry vectors used by threat actors and determine the complete volume of exfiltrated data.
According to the company's Securities and Exchange Commission Form 8-K filing, the stolen files contain a combination of proprietary business records, patient health details, and other confidential internal information. The investigation remains ongoing as forensic teams work to assess the full sensitivity and scope of the compromised records. Amgen implemented additional technical security enhancements to protect surrounding digital infrastructure from further compromise.
Operational Impact and Business Continuity
Despite the exfiltration of sensitive patient and corporate data, Amgen confirmed that the incident has not disrupted its primary commercial or clinical operations. The company stated that it has identified no operational impact on drug manufacturing capabilities, core product supply lines, or financial reporting systems. The drugmaker reassured healthcare partners and investors that its ability to deliver essential medicines and fulfill clinical needs remains unaffected by the security breach.
The incident highlights growing digital threats targeting life sciences corporations, where interconnected cloud infrastructure and vendor ecosystems present lucrative targets for cybercriminal syndicates. Amgen's disclosure underscores the persistent risks associated with third-party cloud environments and the importance of robust security protocols within interconnected business networks.
What is a data breach?+
How did the threat actors access Amgen's cloud systems?+
What types of data were stolen in the Amgen breach?+
Has the breach affected Amgen's ability to produce and deliver medicines?+
Why are healthcare companies vulnerable to cloud-based breaches?+
Bülten Aboneliği
Haftada bir, teknoloji ve dijital dünyadan seçtiklerimiz e-postanda. Spam yok, sadece içerik.


