Skip to content

Amgen

Disclosed Jul 31, 20268 weeks ago39,594 affectedConfirmed

Official notice

Amgen says patient health data exfiltrated from third-party cloud systems

Amgen told the SEC that attackers exfiltrated proprietary data and patient protected health information from cloud environments operated by third-party service providers. It did not expect a material financial impact.

What is known

People affected39,594 (as reported by the organization)
DisclosedJul 31, 2026
DiscoveredJul 2026
HappenedJul 1, 2026
AttackVendor breach
Data exposedHealth, Internal documents, Social Security numbers, Government IDs, Insurance, Payment cards, Financial, Dates of birth, Addresses, Names
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Amgenoag.ca.gov · Official notice
Amgen Inc Form 8-K, Item 1.05 (2026-07-31)sec.gov · SEC filing
Amgen says cloud data breach exposed patient health, proprietary infobleepingcomputer.com · News
Texas Attorney General data security breach report BR-0005264: Amgenoag.my.site.com · Official notice
Vermont Attorney General breach report: Amgenago.vermont.gov · Official notice

Notices filed

WhereFiledPeople
SEC 8-KtotalJul 31
ResearchtotalJul 31
California AGresidents of CAAug 17
Vermont AGresidents of VTAug 1724
Texas AGresidents of TXAug 186,714

Other breaches at Amgen

BreachAffected
Disclosed May 30, 2024May 30, 20242 years agoHacking1.6M
Disclosed Jun 22, 2021Jun 22, 20215 years agoUnknown
Disclosed Jun 26, 2018Jun 26, 20188 years agoUnknown
History of this record
  • 2026-09-25 · source: empty to https://ago.vermont.gov/categories/security-breach-notices · backfill source
  • 2026-09-25 · data_types: ["health","internal-docs"] to ["health","internal-docs","ssn","government-id","insurance","payment-card","financial","dob","addresses","names"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 39594 · backfill source
  • 2026-09-25 · sector: tech to health · seed source
  • 2026-09-25 · attack: unknown to third-party · seed source
  • 2026-09-25 · data_types: [] to ["health","internal-docs"] · seed source
  • 2026-09-25 · discovered: empty to 2026-07 · seed source
  • 2026-09-25 · summary: empty to Amgen told the SEC that attackers exfiltrated proprietary data and patient protected health information from cloud environments operated by third-party service providers. It did not expect a material financial impact. · seed source
  • 2026-09-25 · title: Material cybersecurity incident reported to the SEC (8-K Item 1.05) to Amgen says patient health data exfiltrated from third-party cloud systems · seed source
  • 2026-09-25 · disclosed: 2026-08-17 to 2026-07-31 · backfill source
  • 2026-09-25 · title: empty to Material cybersecurity incident reported to the SEC (8-K Item 1.05) · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Amgen

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.