Amgen has confirmed that hackers stole patient health information, along with confidential research and business data, from cloud storage systems the company uses. The pharmaceutical giant has not yet said how many people are affected or sent out individual notification letters.
Amgen Inc. (NASDAQ: AMGN), the Thousand Oaks, California-based biotechnology company, disclosed in a Securities and Exchange Commission filing that threat actors compromised third-party cloud storage environments containing company information. Amgen determined on July 29, 2026 that the incident was material, given the volume of files involved and the potential sensitivity of the information, and filed its disclosure on July 31, 2026.
A Confirmed Breach, With Notification Still to Come
This is an early-stage disclosure. Amgen’s own SEC filing states that its investigation into the full scope of the exfiltrated data is ongoing, and that it will notify affected patients where required, but the company has not yet released a population figure, an itemized list of exactly what data was taken, or individual notification letters. Amgen says it has not identified any impact to its products, manufacturing operations, or financial reporting systems.
What Information Was Exposed?
Per Amgen’s own SEC disclosure, confirmed exfiltrated data includes:
- Patient Protected Health Information (specific fields not yet itemized)
- Proprietary Business Data, Intellectual Property, and Research Materials (company information, not personal data)
Who May Be Affected?
Amgen has not yet identified a specific affected population. This investigation is currently gathering information from current and former employees, and current and former customers, who believe their information may have been involved, given the nature of the compromised systems.
What Is Amgen Offering?
Not yet disclosed. Because individual notification hasn’t gone out, no credit monitoring or identity protection offer has been announced.
Your Information May Be at Risk
Patient protected health information can include diagnosis, treatment, and other medical details that are difficult or impossible to change once exposed, unlike a password or even a Social Security number. Even before Amgen finishes its investigation and sends formal notice, anyone who believes they may be affected has reason to start watching for suspicious activity and unexpected communications referencing Amgen.
Do You Have Legal Options?
Companies that collect and store patient health information have a legal duty to safeguard it, and that duty applies whether the information belongs to a patient, a current or former employee, or a current or former customer.
If you are a current or former employee, or a current or former customer of Amgen, and believe you were impacted by this data breach, contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.
FAQ
Has Amgen sent notification letters yet?
Not as of this writing. Amgen’s SEC filing states that notification to affected patients will happen where required, but the investigation into the full scope of the breach is still ongoing.
How many people are affected?
Not yet disclosed. Amgen has not released a population figure or a detailed breakdown of exactly whose information was involved.
What information was stolen?
Patient protected health information, along with proprietary business data, intellectual property, and research materials, per Amgen’s own SEC disclosure. The specific health data fields involved haven’t been itemized yet.
Do I have a legal claim?
Companies that collect patient health information have a legal duty to protect it and to notify affected individuals where required. If you are a current or former employee, or a current or former customer of Amgen, and believe you were impacted, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 for a Free Case Review.