Amgen Reveals Attack on Third-Party Cloud Servers: Health Data and Proprietary Information Exposed
Amgen reports a cyberattack on third-party cloud servers, exposing protected health data and trade secrets. The SEC was notified, and HIPAA rules apply.
Illustrative image generated with AI
Discovery of the Intrusion and Immediate Response
In July 2026, biopharmaceutical company Amgen detected unauthorized access to corporate data stored on external cloud providers. The company immediately activated its incident response plan, isolating the affected systems and engaging a team of independent forensic experts. The primary objective was to contain the attack and limit data exfiltration. Amgen has not disclosed the identity of the cloud providers nor specified when the initial breach occurred.
What Was Stolen: PHI and Trade Secrets
Initial checks confirm that the attackers exfiltrated data containing proprietary information and patients' protected health information (PHI). Investigations are still underway to determine whether the haul also includes intellectual property, research and development data, additional medical records, or trade secrets. The presence of PHI immediately raises attention to compliance with U.S. health privacy laws, particularly HIPAA.
The SEC Filing: Why the Incident Is 'Material'
On July 29, 2026, Amgen filed a Form 8-K with the Securities and Exchange Commission, in which it assessed the incident as “material.” The company believes it is unlikely that the event will have a significant impact on its financial condition or operations. Nevertheless, the classification mandates immediate transparency to investors and could accelerate the initiation of legally required notifications to patients and authorities.
The SSO Vishing Hypothesis: An Attack Vector Yet to Be Confirmed
Some press investigations hypothesize that the attack vector was a vishing (voice phishing) attack targeting a corporate Single Sign-On (SSO) account. If confirmed, the attacker would have used legitimate credentials to move laterally and reach data on third-party clouds. Amgen has neither confirmed nor denied this account. At present, the attack has not been attributed to any known criminal or state-sponsored groups.
The Consequences: HIPAA, Notifications, and Uncertainties for Patients
The incident forces Amgen to urgently evaluate mandatory notifications required by HIPAA and other data protection regulations. The number of affected individuals and technical details on remediation actions have not yet been disclosed. As forensic analyses continue, the case reignites the debate on cloud infrastructure security in the pharmaceutical sector, where trade secrets and highly sensitive health data coexist.
Sources
This article is an original reworking based on the sources below.




