Amgen Hit by Patient Data Breach
Synopsis
The pharmaceutical company disclosed a cybersecurity breach involving sensitive patient and corporate information.
Amgen reported a material cyber incident involving the theft of sensitive patient information and confidential company information from cloud storage systems operated by third parties, joining a long list of cyber incidents across the world's healthcare industry.
The biotechnology company concluded, in a filing with the U.S. Securities and Exchange Commission (SEC), that the incident would be considered material as of July 29, 2026, based upon its assessment of the nature and sensitivity of the information.
The investigation is ongoing and Amgen has not revealed how many people were affected or who is responsible for the attack.
Cloud-Based Data Compromised
Amgen patient data breach is not a company-owned system, but data stored in third party cloud solutions. The lost or stolen information can contain patient health information, confidential business records, research and development documents, intellectual property and other proprietary information, according to the SEC filing.
Upon identifying the breach, Amgen initiated its incident response protocols, isolated the impacted environment and brought external cybersecurity and forensic experts in to conduct a thorough investigation, the company said.
The company is also studying its notification obligations in terms of the applicable laws on privacy and data protection.
The company has not yet seen any impact on manufacturing processes, medicine supply, financial reporting systems or capability to supply medicines and services to patients, the company said.
Healthcare Sector Faces Rising Cyber Risks
The revelation follows the ongoing trend of cyberattacks on healthcare institutions, where medical records and research data are of high value. More than 22,000 security incidents were analysed by the 2026 Verizon Data Breach Investigations Report (DBIR), which revealed that exploiting software vulnerabilities has surpassed stolen credentials as the most prevalent way to gain initial access.
The report also noted that third-party service providers were more likely to be involved in a security incident.
Healthcare also topped the list for the 14th year in a row as the most expensive industry to experience a data breach, at US$9.77 million, versus the global cross-industry average of US$4.88 million, according to the 2025 IBM Cost of a Data Breach Report.
According to Amgen's latest quarterly financial results, its revenue for the first quarter of 2026 is projected to reach US$8.15 billion. The company is continuing its investigation and is in compliance with the legal and regulatory reporting process, it said.
Source: Reuters
Pooja Malik is a business journalist with over six years of experience covering startups, entrepreneurship, and emerging trends. She has previously worked with leading media platforms such as YourStory Media and BW BusinessWorld, where she reported on business, policy, and market developments. Currently, she serves as Editor at The Inspirepreneur Magazine, where she writes and edits stories across business, lifestyle, and travel, with a focus on clarity, accuracy, and reader relevance.