Desk live·
ForensicPost
Breaches/Third party/File 26-0806

Amgen Says Patient Health Data Was Taken From Third-Party Cloud Systems

Amgen confirmed that proprietary data and patient health information were taken from cloud environments run by third-party providers. It judged the incident material on 29 July, and said it does not expect a material effect on its financial results.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAmgen
ActorUnattributed
S. Rosler11 min readConfidence: high3 sources reviewed

Amgen disclosed that attackers took corporate and patient data from multiple cloud systems operated by third-party service providers. The company detected unauthorised activity in July 2026, activated its response plan, applied containment measures and engaged independent forensic experts.

It confirmed that data was exfiltrated, including proprietary information and patient protected health information. On 29 July it determined the incident was material, having assessed the volume of potentially affected files and the likelihood that they held sensitive information — while stating it does not currently believe the incident is reasonably likely to materially affect its financial condition or operating results. How the cloud environments were compromised has not been made public.

Two Meanings Of Material, In One Filing

The company judged the incident material for disclosure purposes and simultaneously said it does not expect material financial consequences. Both statements are conventional, both are probably accurate, and together they describe the disclosure regime precisely.

Materiality for a securities filing asks whether a reasonable investor would want to know. Whether patients are harmed is not that question and never has been. We filed the ordering problem at 23-0502, where a company disclosed to the regulator on 2 May and told its employees on the 3rd, and the interval problem at 22-0617. This file adds the definitional one: the trigger for telling anyone is calibrated to the share price.

The Patients Are Two Parties Removed

A person whose health information was in those systems has a relationship with a clinician, possibly with a trial, and at most an indirect one with the pharmaceutical company. They have none whatever with the cloud provider that held the data.

We have recorded this structure as its single most common shape — 26-0713, 23-0614 where a government’s files were 5% of a supplier’s dump, 26-0721b where a billing vendor held 442,000 patients. Amgen is the version where the affected party cannot name either intermediary, and the notification, when it comes, will arrive from a company they may not know holds anything about them.

The Route Is Unpublished, Again

How the third-party cloud environments were reached has not been stated. The corpus audit at 26-0802 found 251 of its files establish no entry route; this becomes another.

That matters more than usual here, because the exposure is shared. Every other customer of those providers has the same question and no way to answer it, and a disclosure that establishes what was taken but not how tells the affected population everything except the one thing that would let anyone else act.

How we reported this

Compiled from the company’s securities disclosure and contemporaneous reporting of it, listed below. No entry route, actor, affected-individual count or provider name has been published and none is asserted here. Notification obligations were described as under evaluation at the time of writing. Graded high on the disclosure. Corrections: corrections@forensicpost.com.

Sources
  1. Amgen says cloud data breach exposed patient health, proprietary infoBleepingComputer
  2. Biotech giant Amgen says patient data stolen from third-party cloud systemsThe Record
  3. Amgen Announces Cyberattack and Data Breach Involving Patient DataHIPAA Journal
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary