Corruption Files
Amgen headquarters in Thousand Oaks, California, where the biotech company disclosed a cybersecurity breach affecting patient data.
Medical Fraud

Amgen Reports Patient Data Breach After Hackers Access Healthcare Information

By

Biotech giant Amgen said Tuesday it was the target of a cyberattack that resulted in the theft of patient health information and proprietary company data from systems run by third-party providers of cloud storage—the latest big healthcare data breach to rock the industry. The California corporation, which posted revenue of roughly $37 billion in fiscal year 2025, disclosed the unauthorized activity in its cloud environments in July and filed a notice with the U.S. Securities and Exchange Commission on July 31, 2026.

Amgen said it initiated its cybersecurity response plan, taking containment steps and engaging outside forensic specialists to investigate the compromise. The investigation confirmed that attackers had exfiltrated company information, including proprietary data, patients' protected health information, and other sensitive records.

Material Incident and Ongoing Investigation

On July 29, Amgen determined the incident was "material," based on its evaluation of how many files appeared to be affected and the possibility that the information in those files could be sensitive. However, the company said it has not identified any disruption to its products, manufacturing operations, financial reporting systems, or its ability to supply medicines to patients. "The incident is not reasonably likely to have a material impact on the company's financial condition or results of operations," Amgen added.

The investigation remains ongoing, and Amgen said it is still assessing whether confidential business information, intellectual property, research and development data, or additional patient information was accessed or stolen. The company has not disclosed how the attackers gained access to the cloud environments or identified the affected cloud providers. Nor did Amgen connect the penetration to any particular threat actor, and no cyber crime group has publicly claimed responsibility for the hack.

Healthcare’s Rising Cybersecurity Threats

There have been more cyberattacks on the healthcare industry by nation-state actors and cybercriminals. Amgen’s compromise is among an increasing number of cybersecurity problems in the biopharma industry, which often includes high-value intellectual property and sensitive patient details. Just weeks prior to Amgen’s disclosure, Novo Nordisk was also hit with a breach of its internal IT systems, with two cyberextortion groups demanding multi-million dollar ransoms.

Pennsylvania-based West Pharmaceutical Services said in May 2026 that it suffered a ransomware attack that affected systems required to make, package and receive medicines after hackers seized data and locked parts of its network. In August 2025, Indiana-based medicinal development firm Inotiv stated it was forced to lock down crucial systems after a ransomware attack. The Qilin ransomware group later claimed credit.

Amgen said it plans to notify affected patients and takes its obligation to safeguard the privacy and security of its patients' data very seriously. The company is one of the world's largest biotechnology companies, with a market capitalization of approximately $207.8 billion. Its most well-known products are Prolia and Xgeva for osteoporosis and bone-related illnesses and Kyprolis and Lumakras for cancer treatment.

Corruption Files — Investigative Journalism
Ruth Anselmi — author photo
About Author

Ruth trained as a pharmacist and then spent a decade watching the gap between clinical trial data and real-world outcomes grow wider every year. She left the industry after a whistleblower case she had quietly supported was settled out of court under a non-disclosure agreement. Her reporting cuts through press releases and FDA approval language to ask the questions that should have been asked before the drug reached the shelf.

SubstackMedium

Related posts