05/08/2026
Amgen disclosed in a filing with the US Securities and Exchange Commission that attackers stole patient protected health information and proprietary company data from cloud systems operated by third-party service providers, not from Amgen's own network. The company detected unauthorised activity in July 2026 and concluded on 29 July 2026 that the incident was material, based on the volume of records involved and the sensitivity of the data. Amgen says it activated its incident response plan, contained the activity and engaged outside forensic investigators, and reports no disruption to its products, manufacturing, financial reporting or supply of medicines.
Several details are unconfirmed: Amgen has not named the cloud providers, explained how the systems were accessed, given a number of affected people, or attributed the attack. The third-party risk pattern is supplier cloud exposure: regulated data held in an external provider's systems can be taken without any attacker touching the company's own network, yet the breach notification, regulatory exposure and reputational cost stay with the data owner.
https://zurl.co/RaQRT
Amgen told the SEC that patient health data and proprietary information were stolen from third-party cloud systems, not its own network. What it means for supplier cloud risk.