Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Amgen Declares Material Cybersecurity Breach After Cloud Data Theft

Amgen Declares Material Cybersecurity Breach After Cloud Data Theft

By:
Last updated:August 4, 2026
Human Written
  • In July of this year, hackers managed to access sensitive medical data from Amgen by circumventing the cloud system of its third-party partners, leading the firm to declare the event a “material” security incident.

  • The breach reflects similar attacks on other companies such as Novo Nordisk and Novartis, which indicates that pharmaceutical firms face rising risks of cyberattacks targeting their valuable intellectual property and confidential patient data.

  • Amgen has initiated a thorough investigation of the extent of the compromised information and also is preparing to notify the impacted clients.

Amgen Declares Material Cybersecurity Breach After Cloud Data Theft

California-based biotech giant Amgen suffered a major cybersecurity breach in July. Hackers accessed the cloud storage systems of the company hosted by third-party providers.

The intruders stole sensitive patient health information and proprietary company data. Amgen disclosed the incident in a securities filing with the SEC on July 29.

The company activated its cybersecurity response plan and immediately discovered an unauthorized activity. Later, forensic investigators confirmed that attackers exfiltrated data from the cloud systems of the company.

Amgen stated the incident has not affected its products or manufacturing operations. The company also said its financial reporting systems remain unaffected. However, Amgen determined the breach is “material” and continues investigating its full scope.

Amgen plans to notify affected patients. The company is assessing whether additional information, including intellectual property and research data, was accessed.

The exact method of compromise remains undisclosed; no ransomware group has claimed responsibility for the attack.

What Data was Stolen

The investigation confirmed that hackers stole proprietary data and the protected health information of patients. Other sensitive records were also exfiltrated from the cloud systems.

Amgen has not revealed how many people that might be in danger. The company is still considering whether the breach has compromised any sensitive business information or research.

The breach involved cloud storage systems managed by external service providers. Amgen has not identified which providers were involved. The company is working with forensic experts to determine the full scope. It is also evaluating legal and regulatory notification requirements under laws like HIPAA.

Biotechnology firms have valuable intellectual assets and private information of patients. Therefore, they are a target for criminals. The past few years have shown an increase in cases of attacks on pharmaceutical companies.

These attacks may result in the leakage of pharmaceutical research information and clinical trial results as well as personal health information.

Similar Attacks Hit Other Drugmakers

The Amgen breach follows a pattern of cybersecurity incidents across the biopharma sector. Just weeks earlier, Novo Nordisk fell victim to a similar attack.

Hackers accessed the internal IT systems of the company and stole clinical trial patient data. Two cyber extortion groups, FulcrumSec and TheUSERS007, demanded a $25 million ransom.

Novo Nordisk refused to pay the ransom; instead, it advised affected patients to remain vigilant if their information appears online. The stolen data consists of anonymized information about patients, such as birth years, biomarkers, and lifestyle information. Names and other direct identifiers were not exposed.

In 2022, Novartis fell victim to the Industrial Spy hackers. The hackers stole details related to its DNA and RNA technologies and tried to sell this information online. These two incidents show how dangerous things are for pharmaceutical firms.

The threat extends beyond the private sector, government agencies are also prime targets, as demonstrated by a recent cyberattack on the European Commission that hackers claim resulted in a 350GB data breach.

What Security Experts Say About the Attack

Security researchers warned about this type of attack months before Amgen disclosed the breach. Silent Push, a threat intelligence firm, mapped adversary infrastructure targeting Amgen back in January this year.

The company identified Amgen among more than 100 large organizations that attackers had staged for single sign-on account takeover. About seven months passed between the January warning and the July disclosure of Amgen.

The attack likely involved social engineering aimed at the helpdesk of a vendor. Someone is posing as internal IT staff. They persuade a representative to reset multi-factor authentication on an employee’s account.

The weak point here is the human process. The attacker never has to defeat a technical control. That reset gives them a signed-in session. That session reaches the cloud apps the account can open. From there, the group pulls data out of connected platforms.

Health-ISAC, a risk management association for the health sector, issued a warning that highlighted the pattern. Once attackers compromise a single SSO account, it would give them access to numerous cloud applications.

Among these apps include platforms such as Salesforce, Microsoft 365, and SharePoint. Once in, hackers retrieve data at their convenience without any detection.

AI and Cybersecurity Risks

The rise of artificial intelligence brings new cybersecurity challenges. In the case of Novo, TheUSERS007 claimed to have used an AI engine called Venomware to gain access.

The group said the self-learning system helped them breach the drugmaker’s defenses. This represents a new frontier in cyber threats.

Major AI developers have also disclosed unusual incidents. OpenAI and Anthropic recently reported that their AI systems broke out of testing environments. The systems allegedly hacked other companies. These events raise concerns about the need for stronger cyber defenses.

Amgen has established an AI Governance Council composed of cross-functional leadership. The council oversees the company’s safe adoption of third-party AI services. The company follows the NIST Trustworthy AI framework for its AI systems, and a Cybersecurity and Digital Trust team handles overall cybersecurity responsibilities.

The biotech industry is among the most likely targets for hackers. The fact that they possess valuable intellectual property and sensitive patient information attracts clever attackers. Companies will have to continue to work on their safety systems to confront the ongoing growing threats.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.