Amgen
Disclosed Jul 31, 20268 weeks ago39,594 affectedConfirmed
Amgen says patient health data exfiltrated from third-party cloud systems
Amgen told the SEC that attackers exfiltrated proprietary data and patient protected health information from cloud environments operated by third-party service providers. It did not expect a material financial impact.
What is known
| People affected | 39,594 (as reported by the organization) |
|---|---|
| Disclosed | Jul 31, 2026 |
| Discovered | Jul 2026 |
| Happened | Jul 1, 2026 |
| Attack | Vendor breach |
| Data exposed | Health, Internal documents, Social Security numbers, Government IDs, Insurance, Payment cards, Financial, Dates of birth, Addresses, Names |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Amgenoag.ca.gov · Official notice | Official notice |
| Amgen Inc Form 8-K, Item 1.05 (2026-07-31)sec.gov · SEC filing | SEC filing |
| Amgen says cloud data breach exposed patient health, proprietary infobleepingcomputer.com · News | News |
| Texas Attorney General data security breach report BR-0005264: Amgenoag.my.site.com · Official notice | Official notice |
| Vermont Attorney General breach report: Amgenago.vermont.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| SEC 8-Ktotal | Jul 31 | |
| Researchtotal | Jul 31 | |
| California AGresidents of CA | Aug 17 | |
| Vermont AGresidents of VT | Aug 17 | 24 |
| Texas AGresidents of TX | Aug 18 | 6,714 |
Other breaches at Amgen
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed May 30, 2024May 30, 20242 years agoHacking | May 30, 20242 years ago | Hacking | Tech | Confirmed | 1.6M |
| Disclosed Jun 22, 2021Jun 22, 20215 years ago | Jun 22, 20215 years ago | Not stated | Tech | Confirmed | Unknown |
| Disclosed Jun 26, 2018Jun 26, 20188 years ago | Jun 26, 20188 years ago | Not stated | Tech | Confirmed | Unknown |
History of this record
- 2026-09-25 · source: empty to https://ago.vermont.gov/categories/security-breach-notices · backfill source
- 2026-09-25 · data_types: ["health","internal-docs"] to ["health","internal-docs","ssn","government-id","insurance","payment-card","financial","dob","addresses","names"] · backfill source
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 39594 · backfill source
- 2026-09-25 · sector: tech to health · seed source
- 2026-09-25 · attack: unknown to third-party · seed source
- 2026-09-25 · data_types: [] to ["health","internal-docs"] · seed source
- 2026-09-25 · discovered: empty to 2026-07 · seed source
- 2026-09-25 · summary: empty to Amgen told the SEC that attackers exfiltrated proprietary data and patient protected health information from cloud environments operated by third-party service providers. It did not expect a material financial impact. · seed source
- 2026-09-25 · title: Material cybersecurity incident reported to the SEC (8-K Item 1.05) to Amgen says patient health data exfiltrated from third-party cloud systems · seed source
- 2026-09-25 · disclosed: 2026-08-17 to 2026-07-31 · backfill source
- 2026-09-25 · title: empty to Material cybersecurity incident reported to the SEC (8-K Item 1.05) · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.