Amgen has disclosed a significant cybersecurity breach in which hackers stole sensitive patient health information and proprietary company data from its cloud systems.
The California-based drugmaker identified unauthorised activity within cloud storage systems hosted by external service providers in July, triggering its cybersecurity response plan.
Containment measures were activated promptly, but a subsequent forensic investigation confirmed that attackers had successfully exfiltrated data before those efforts took effect.
“The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments,” Amgen said in a Form 8-K filing with the SEC.
Amgen formally classified the incident as a material cybersecurity event on July 29 after assessing the number of affected files and the potential sensitivity of the information they contained.
The breach was subsequently disclosed to the US Securities and Exchange Commission on July 31, fulfilling the company’s obligations under securities regulations governing material incidents.
Despite the severity of the intrusion, Amgen stated it “has not identified any impact” to its products, manufacturing operations, financial reporting, or delivery of medicines to patients.
The company added that the breach is “not reasonably likely to have a material impact on the Company’s financial condition or results of operations,” though its investigation into the full scope of compromised records remains ongoing.
Amgen said it plans to notify affected patients, and investigators are still assessing whether confidential business data, intellectual property, or research and development material was also accessed or stolen.
The company has not confirmed any connection to a specific threat actor, though cybersecurity researchers have been investigating whether the extortion group known as ShinyHunters, which has claimed responsibility for a series of healthcare-sector breaches in 2026, played a role.
The incident adds to a rapidly growing list of cyberattacks targeting the biopharma sector, which holds significant volumes of high-value intellectual property and sensitive patient records.
Novo Nordisk fell victim to a breach of its internal IT systems just weeks ago, accompanied by multi-million-dollar ransom demands from two cyberextortion groups, FulcrumSec and TheUSERS007.
Unmatched clinical trial participant information was among the data that hackers accessed in the Novo Nordisk attack, highlighting the particular vulnerability of research-stage medical data.
Abbott Laboratories, Clover Health, Stryker, Medtronic, and West Pharmaceutical Services have also recently been affected by cyberattacks or security disruptions of varying severity.
Healthcare organisations remain attractive targets for criminal groups because their systems can contain extensive collections of medical, identity, financial, and commercially sensitive information in one place.

