
Amgen told the US SEC that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from its own network. The company concluded the incident was material on 29 July 2026. It says medicine supply was not affected. The lesson: data placed in a supplier's cloud is still the owner's breach to disclose.
Amgen, one of the world's largest biotechnology companies, told the US Securities and Exchange Commission that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from Amgen's own network. The company detected the intrusion in July 2026 and concluded on 29 July 2026 that the incident was material. Amgen says its ability to make and supply medicines was not affected. The lesson: data a company places in a supplier's cloud is still that company's breach to disclose and defend.
What happened
In a filing with the SEC, Amgen said it found unauthorised activity in July 2026 involving data held in cloud environments operated by third-party service providers. It concluded the incident was material on 29 July 2026, based on the volume of records involved and the sensitivity of the information. The company says the stolen data includes proprietary corporate information, patients' protected health information (health data that identifies a person), and other sensitive records. Amgen states it activated its incident response plan, contained the activity and engaged outside forensic investigators. It reports no disruption to its products, manufacturing, financial reporting or supply of medicines.
Several details are unconfirmed. Amgen has not named the cloud providers involved, said how the systems were accessed, given a number of affected people, or attributed the attack to a known group. The company has said it will notify individuals and regulators as required once its review identifies who was affected.
Why it matters for third-party risk
The pattern is supplier cloud exposure. Large companies store regulated data in systems run by outside providers: software vendors, analytics platforms, managed cloud services. That data can be taken without any attacker touching the company's own network. Amgen's core operations kept running, yet the records that leaked were its responsibility. The breach notification, the regulatory exposure and the reputational cost stay with the data owner, not the provider that was breached. A well-defended perimeter does not cover data that lives somewhere else.
What teams should take from it
Two takeaways. First, keep an inventory of which suppliers hold your regulated data, and where. A material breach can happen in a system you do not operate and cannot directly see. Second, treat cloud and software vendors as in scope for incident drills, not just your own infrastructure. If a provider is slow to detect or report, your disclosure clock and your customers' exposure are already moving. Contracts should fix detection, notification and forensic-access terms before an incident, not during one.
For teams sizing this exposure, it is worth reviewing how continuous vendor monitoring narrows the gap between a supplier's breach and your response.
FAQ
Was Amgen's own network breached?
Amgen says the affected data sat in cloud systems operated by third-party service providers, not in its own systems. It reports no disruption to manufacturing, financial reporting or medicine supply.
What data was taken?
According to Amgen's SEC filing, the stolen data includes proprietary company information and patients' protected health information, along with other sensitive records. The number of affected individuals has not been disclosed.
Why did Amgen call the incident material?
Amgen concluded on 29 July 2026 that the incident was material based on the volume of records involved and the sensitivity of the data. Under SEC rules, a material determination triggers a duty to disclose the incident.
Want this applied to your supplier ecosystem? See the platform in action and map your top vendor risks live in one walkthrough.


