Amgen Inc. , a Thousand Oaks, CA-based biopharmaceutical company that develops and manufactures pharmaceutical products for oncological, hematological, and cardiovascular diseases, has recently disclosed a cybersecurity incident involving unauthorized access to third-party-hosted cloud storage systems. In a Form 8-K filing with the U.
S. Securities and Exchange Commission (SEC), Amgen explained that it determined in July 2026 that hackers gained access to certain cloud systems. Amgen immediately implemented its cybersecurity response plan, deployed containment measures, and engaged third-party digital forensics experts to determine the nature and scope of the unauthorized activity.
The investigation determined that proprietary data, patients’ protected health information, and other data had been exfiltrated from the cloud environment, and on July 29, 2026, determined that the incident was material and informed the SEC. Amgen said it does not believe the incident is reasonably likely to have an impact on its financial position, nor any of its products, manufacturing operations, financial reporting systems, or its ability to meet patient needs.
Amgen is in the process of assessing the extent to which patient information, confidential business information, intellectual property, research and development, and other information was exfiltrated in the attack and will be unable to accurately determine the impact to the company until those processes have concluded. At present, the exact nature of the attack, such as how the cloud systems were compromised, has yet to be made public.
Amgen said it takes the protection of its systems and data very seriously and is in the process of determining the applicable regulatory and legal notification requirements, including its responsibilities under HIPAA. As of the date of the SEC filing, the threat group behind the attack is unclear. Several pharmaceutical, biotechnology, and medtech firms have fallen victim to cyberattacks in recent months, including Novo Nordisk , Medtronic , Stryker , Abbott Laboratories , West Pharmaceutical Services, and Brainyx AI.
The attacks have been conducted by several threat actors, including the Iran-linked hacktivist group Handala and the data theft and extortion groups FulcrumSec and ShinyHunters. The latter was the subject of a recent cybersecurity alert by Health-ISAC after a string of successful hacks on the healthcare sector. The post AmGen Announces Cyberattack and Data Breach Involving Patient Data appeared first on The HIPAA Journal .
Originally published at hipaajournal.com
