Home / The Long Read / Research
Long Read

Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen told the US SEC that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from its own network. The company concluded the incident was material on 29 July 2026. It says medicine supply was not affected. The lesson: data placed in a supplier's cloud is still the owner's breach to disclose.

Amgen says patient data was stolen from third-party cloud systems, not its own network
TL;DR

Amgen told the US SEC that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from its own network. The company concluded the incident was material on 29 July 2026. It says medicine supply was not affected. The lesson: data placed in a supplier's cloud is still the owner's breach to disclose.

Amgen, one of the world's largest biotechnology companies, told the US Securities and Exchange Commission that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from Amgen's own network. The company detected the intrusion in July 2026 and concluded on 29 July 2026 that the incident was material. Amgen says its ability to make and supply medicines was not affected. The lesson: data a company places in a supplier's cloud is still that company's breach to disclose and defend.

Amgen breach (disclosed 31 July 2026): the data sat in a supplier's cloud Attackers took Amgen data from cloud systems run by third-party providers, not from Amgen's own network. Attacker accessed and exfiltrated records (method unconfirmed) Third-party cloud systems operated by external service providers, holding Amgen data Reported taken: patient protected health information proprietary company data providers not named; access method unconfirmed Downstream exposure Patients whose health data was taken Amgen intellectual property SEC material-incident disclosure duty Breach-notification and reputational cost The data owner answers for the breach, not the provider that was compromised. What Amgen stated (SEC filing, 31 July 2026): incident concluded material on 29 July 2026; no disruption to products, manufacturing or medicine supply. Third-party risk, in one line: A strong perimeter does not protect regulated data that lives in a supplier's cloud; the owner still carries the breach. Sources: Amgen SEC 8-K, The Record, BleepingComputer, HIPAA Journal. Draft diagram for Breach Wire, Supplier Shield.

What happened

In a filing with the SEC, Amgen said it found unauthorised activity in July 2026 involving data held in cloud environments operated by third-party service providers. It concluded the incident was material on 29 July 2026, based on the volume of records involved and the sensitivity of the information. The company says the stolen data includes proprietary corporate information, patients' protected health information (health data that identifies a person), and other sensitive records. Amgen states it activated its incident response plan, contained the activity and engaged outside forensic investigators. It reports no disruption to its products, manufacturing, financial reporting or supply of medicines.

Several details are unconfirmed. Amgen has not named the cloud providers involved, said how the systems were accessed, given a number of affected people, or attributed the attack to a known group. The company has said it will notify individuals and regulators as required once its review identifies who was affected.

Why it matters for third-party risk

The pattern is supplier cloud exposure. Large companies store regulated data in systems run by outside providers: software vendors, analytics platforms, managed cloud services. That data can be taken without any attacker touching the company's own network. Amgen's core operations kept running, yet the records that leaked were its responsibility. The breach notification, the regulatory exposure and the reputational cost stay with the data owner, not the provider that was breached. A well-defended perimeter does not cover data that lives somewhere else.

What teams should take from it

Two takeaways. First, keep an inventory of which suppliers hold your regulated data, and where. A material breach can happen in a system you do not operate and cannot directly see. Second, treat cloud and software vendors as in scope for incident drills, not just your own infrastructure. If a provider is slow to detect or report, your disclosure clock and your customers' exposure are already moving. Contracts should fix detection, notification and forensic-access terms before an incident, not during one.

For teams sizing this exposure, it is worth reviewing how continuous vendor monitoring narrows the gap between a supplier's breach and your response.

FAQ

Was Amgen's own network breached?

Amgen says the affected data sat in cloud systems operated by third-party service providers, not in its own systems. It reports no disruption to manufacturing, financial reporting or medicine supply.

What data was taken?

According to Amgen's SEC filing, the stolen data includes proprietary company information and patients' protected health information, along with other sensitive records. The number of affected individuals has not been disclosed.

Why did Amgen call the incident material?

Amgen concluded on 29 July 2026 that the incident was material based on the volume of records involved and the sensitivity of the data. Under SEC rules, a material determination triggers a duty to disclose the incident.

What to do next

Want this applied to your supplier ecosystem? See the platform in action and map your top vendor risks live in one walkthrough.

Read next

Xsolis breach reached hospital patients through one shared healthcare AI vendor

Xsolis breach reached hospital patients through one shared healthcare AI vendor

A phishing attack at Xsolis, a US healthcare vendor that many hospitals and insurers use to review whether care is covered, exposed the data of about 1.4 million people. Patients at Mayo Clinic, UW Medicine and VHC Health were among those affected, because one vendor held records from many providers at once.

Read article
SonicWall SMA 1000 zero-days under active attack: the remote-access appliance became the way in

SonicWall SMA 1000 zero-days under active attack: the remote-access appliance became the way in

On 14 July 2026 SonicWall confirmed two actively exploited zero-days in its Secure Mobile Access (SMA) 1000 Series remote-access appliances and released fixed firmware. The pattern is concentration risk at the network edge: a widely used SSL VPN gateway sits in front of internal systems, so its compromise reaches everyone behind it, including the clients of managed providers that run one.

Read article
Jscrambler's own npm package was hijacked: a trusted supplier became a supply-chain vector

Jscrambler's own npm package was hijacked: a trusted supplier became a supply-chain vector

An attacker hijacked Jscrambler's npm package with a stolen publishing credential and shipped an infostealer to developers between 11 and 13 July 2026. The malware harvested cloud tokens, wallets and AI-assistant credentials from any machine that installed it. For third-party risk teams, the lesson is that a trusted dependency is a supplier, and its release channel can become the attack path.

Read article