Biotech giant Amgen says patient data stolen from third-party cloud systems
The California-based biotechnology company Amgen said patient information and proprietary company data was stolen from cloud systems operated by third-party providers.
In a filing with the Securities and Exchange Commission on Friday, the company said it detected unauthorized activity in July involving data stored in cloud environments hosted by external service providers.
The investigation found that attackers exfiltrated company information, including proprietary data, patients' protected health information, and other sensitive records.
Amgen said it has not identified any disruption to its products, manufacturing operations, financial reporting systems, or its ability to supply medicines to patients.
"The incident is not reasonably likely to have a material impact on the company's financial condition or results of operations," Amgen added.
The investigation remains ongoing, and Amgen said it is still assessing whether confidential business information, intellectual property, research and development data, or additional patient information was accessed or stolen. The company said it plans to notify affected patients.
Amgen did not disclose how the attackers gained access to the cloud environments or identify the affected cloud providers. It also did not attribute the intrusion to any threat actor.
There is no public indication that ransomware was involved, and no cybercriminal group has claimed responsibility for the breach.
Amgen is one of the world's largest biotechnology companies, with a $207.8 billion market cap. Its best-known products include Prolia and Xgeva for osteoporosis and bone-related diseases, as well as Kyprolis and Lumakras for cancer treatment.
The healthcare industry has faced a growing number of cyberattacks from both nation-state actors and cybercriminals.
In May, Pennsylvania-based West Pharmaceutical Services said a ransomware attack disrupted systems used to manufacture, ship, and receive products after attackers stole data and encrypted parts of its network. In August 2025, Indiana-based drug research company Inotiv said a ransomware attack forced it to shut down critical systems, with the Qilin ransomware gang later claiming responsibility.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



