Amgen Data Breach Exposes Patient Health Information and Proprietary Data

Pharmaceuticals data breach illustration
Breach Discovery: July 2026Breach Notification: July 2026

What Happened in the Amgen Data Breach?

Amgen Inc., one of the world’s largest biotechnology companies, has confirmed a serious cybersecurity incident involving its cloud-based data storage. The company disclosed in a filing with the Securities and Exchange Commission that attackers gained unauthorized access to data held in cloud environments operated by third-party service providers. This discovery came in July 2026, when Amgen’s security team first identified suspicious activity within these systems.

As a result of the discovery, Amgen activated its cybersecurity response plan right away. The company said it implemented containment measures and brought in independent forensic experts to determine the scope of the intrusion. Because the investigation is ongoing, Amgen has not yet released full details about how the attackers gained entry or how long they had access before being detected.

Importantly, Amgen has confirmed that data was actually taken, not merely viewed or potentially exposed. The company stated that proprietary data, patient protected health information, and other information were exfiltrated from the affected cloud environments. On July 29, 2026, after reviewing the volume and sensitivity of the impacted files, Amgen formally determined the incident to be material under SEC disclosure rules.

The forensic investigation remains active as Amgen works to determine the full extent of what was accessed. According to the company, it continues to assess whether patient information, confidential business records, intellectual property, and research and development data were compromised. Amgen has stated that, so far, it has found no evidence the incident affected its manufacturing operations, product safety, or its ability to supply medications to patients.

Who was affected?

Because the investigation is still underway, Amgen has not publicly disclosed a specific number of affected individuals. The company has, however, confirmed that patient protected health information was among the data types exfiltrated. This suggests the breach may affect people who received care involving Amgen products or who participated in programs tied to the company’s pharmaceutical operations.

In addition to patients, the exposure of proprietary and confidential business information suggests employees or business partners could also be affected. Amgen operates globally, but as a US-based pharmaceutical company headquartered in Thousand Oaks, California, its patient data programs and operations touch a large population of US residents. The company has said it will notify all impacted patients once its review is complete.

What Information Was Potentially Exposed?

Amgen’s SEC filing identifies several categories of information involved in the breach. While the company has not released a complete technical breakdown, it did specify the types of data that were confirmed as exfiltrated from its cloud systems.

  • Patient protected health information
  • Proprietary company data
  • Confidential business information
  • Potentially research and development data
  • Other unspecified company information

When protected health information is stolen, the risks for affected patients can be significant. Health data often includes details about medical conditions, treatments, or prescriptions, which criminals can use for medical identity theft. This type of fraud can lead to false insurance claims or incorrect information being added to a victim’s medical history, which can be difficult and time-consuming to correct.

Beyond health-related risks, the theft of proprietary and confidential business information raises separate concerns. If intellectual property or research data was accessed, this could affect Amgen’s competitive position, though that is a corporate risk rather than a direct consumer harm. For patients, however, the exposure of personal health details remains the primary concern, since this information is highly valuable to scammers who target vulnerable individuals with fraud schemes.

What is the company doing?

Once Amgen identified the unauthorized activity, it moved to contain the incident quickly. The company engaged independent cybersecurity forensic specialists to investigate the scope and cause of the breach. This step is standard practice for organizations responding to significant intrusions, as it helps determine exactly what data was accessed and how the attackers gained entry.

Amgen has also stated that it is evaluating its obligations under applicable privacy and data breach notification laws. The company said it will notify all impacted patients as required once its assessment is finalized. Additionally, Amgen noted that it takes its responsibility to protect patient data seriously and continues to monitor for any further impact on its business operations, including manufacturing and product supply.

Because the investigation is ongoing, Amgen has indicated it may amend its regulatory filing as more information becomes available. This means further details about the scope of the breach, including the number of affected individuals and specific data elements involved, could be released in the coming weeks or months.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone who receives a notification from Amgen about this breach should begin monitoring their credit reports closely. Regularly reviewing your credit report can help you catch unauthorized accounts or suspicious activity early, before it causes lasting financial damage.

You can request free credit reports from each of the three major credit bureaus through AnnualCreditReport.com. Because this breach involved sensitive personal data, it may be worth checking your reports more frequently than usual over the next year, especially if you receive a formal notification letter from Amgen.

Watch for Phishing and Medical Scams

Since patient health information may have been exposed, affected individuals should stay alert for phishing emails, calls, or texts that reference medical treatments or insurance details. Scammers often use stolen health data to make fraudulent messages seem more convincing.

Never click on links or provide personal information in response to unsolicited messages, even if they appear to come from a legitimate healthcare provider or insurer. Instead, contact the organization directly using a phone number or website you know to be authentic. This simple habit can prevent many identity theft attempts before they succeed.

Review Medical and Insurance Records

Because protected health information was involved in this breach, affected patients should review their medical records and insurance statements for any unfamiliar entries. Medical identity theft can result in fraudulent claims being filed under your name, which may affect your coverage or care in the future.

If you notice any treatments, prescriptions, or charges you do not recognize, contact your healthcare provider and insurance company right away. Correcting inaccurate medical records early can prevent complications down the road, including denied claims or incorrect treatment recommendations based on false information.

Consider a Fraud Alert or Credit Freeze

Given that sensitive personal and health information was exfiltrated, placing a fraud alert or credit freeze on your credit files is a reasonable precaution. A fraud alert requires lenders to take extra steps to verify your identity before opening new credit in your name.

A credit freeze offers even stronger protection by restricting access to your credit report entirely. As a result, most identity thieves cannot open new accounts in your name while the freeze is active. Both options are free and can be requested directly through each credit bureau.

Consult a Data Breach Attorney

If you receive notice that your information was involved in this incident, it may be worth speaking with an attorney who focuses on data breach cases. An attorney can help you understand your legal rights and whether you may be eligible to join a class action or seek compensation.

Many data breach attorneys offer free consultations, so there is little downside to exploring your options. This is especially true when sensitive health information is involved, since the potential harm to affected patients can be more severe than in breaches involving only basic contact details.



More Information

Official data breach notification from Delaware Attorney General

Related Data Breaches

See the latest data breaches we're tracking →