Amgen Inc. has disclosed a material cybersecurity incident after identifying unauthorized activity involving data stored in cloud environments hosted by third-party service providers. The company revealed the incident in a Current Report on Form 8-K filed with the U.S. Securities and Exchange Commission (SEC).
According to the filing, Amgen detected the unauthorized activity in July 2026 and immediately activated its cybersecurity incident response plan. The company implemented containment measures and engaged independent cybersecurity forensic experts to investigate the breach.
The investigation has since confirmed that certain data was exfiltrated from the affected cloud environments. The compromised information includes proprietary business data, patient protected health information (PHI), and other sensitive information. Amgen stated that the investigation is ongoing and it is continuing to determine the full scope of the incident, including whether confidential business information, intellectual property, research and development data, or additional patient information was accessed or stolen.
Despite the breach, Amgen emphasized that there has been no identified impact on its products, manufacturing operations, financial reporting systems, or its ability to supply medicines to patients. The company also stated that, based on its current assessment, the incident is not reasonably expected to have a material impact on its financial condition or operating results.
On July 29, 2026, after evaluating the volume of affected files and the potentially sensitive nature of the information involved, Amgen determined that the cybersecurity incident met the threshold for materiality, requiring disclosure under SEC cybersecurity reporting rules.
The biotechnology company said it is reviewing all applicable legal and regulatory notification obligations and will notify affected patients and relevant authorities where required. Amgen reiterated that protecting patient privacy and data security remains a priority and noted that additional information may be disclosed through an amended Form 8-K as the investigation progresses.
The incident highlights the growing cybersecurity risks facing the pharmaceutical and biotechnology industry, particularly as organizations increasingly rely on cloud-based infrastructure to store sensitive research, business, and patient information.


