2026 Amgen — third-party cloud breach; patient PHI exfiltrated (SEC 8-K)
Data compromised
Proprietary company data, patient protected health information (PHI), and other information exfiltrated from third-party cloud environments (per Form 8-K); full patient census TBD — notifications forthcoming
Technical writeup
Verified SEC Form 8-K (Item 1.05) — event date July 29, 2026. Amgen Inc. identified unauthorized activity in July 2026 involving data stored in cloud environments hosted by third-party providers, activated incident response, contained, and engaged forensic experts. Some company data — including proprietary data, patient protected health information, and other information — was exfiltrated. Amgen reported no identified impact to products, manufacturing, financial reporting, or ability to meet patient needs as of the filing. On July 29 it determined the incident material based on volume of apparently impacted files and sensitivity. Investigation ongoing regarding extent of patient/CBI/IP/R&D exposure; company will make required patient/regulatory notifications. recordsAffected 0 pending attested census. Distinct from prior Amgen CA AG stub rows and Change Healthcare downstream notices.
Root cause
Unauthorized activity involving data in third-party cloud storage environments (identified July 2026); files including patient PHI exfiltrated; deemed material July 29, 2026