Amgen, the California biotechnology company behind drugs like Enbrel and Repatha, has confirmed a data breach that exposed patient health information and proprietary company data after attackers accessed cloud environments run by outside service providers. In a filing with the U.S. Securities and Exchange Commission dated 29 July 2026, Amgen said it had formally determined the incident to be "material" — a designation reserved for breaches significant enough that investors must be told — after reviewing the volume and sensitivity of the files involved.
According to the filing, Amgen detected the unauthorized activity in cloud systems operated by third parties, then activated its cybersecurity response plan, engaged independent forensic investigators, and began containment. The company confirmed that some of what was taken included patients' protected health information alongside proprietary business data, but it has not disclosed how many patients are affected, which cloud providers were involved, or how the attackers got in. Amgen says the breach has not touched its manufacturing operations, financial reporting systems, or its ability to supply medicines, and it does not currently expect a material impact on its financial results. The company says it is still evaluating its legal and notification obligations and will contact affected patients where required. Amgen has not named a suspect, and any online speculation about who is responsible remains unconfirmed.
What this means for your business
You don't need to be a pharmaceutical company holding patient records to take a lesson from this one. Sensitive customer, patient, or employee data increasingly lives with third-party cloud and SaaS vendors rather than on servers you control — and when one of those vendors is breached, it's your data exposed and your customers to notify, even though your own systems were never touched. If you're not sure which vendors hold your most sensitive data today, that's worth finding out before an incident forces the question.
Two practical steps this week: first, list every third-party service that stores customer or employee personal data on your behalf, and check what each one's contract actually says about breach notification timing — a vague "we'll let you know" clause is not a plan. Second, limit what you hand vendors in the first place; a system that never receives a field of sensitive data can't leak it. Amgen's own disclosure shows the difference good incident response makes: a documented response plan, forensic experts on standby, and a clear public statement, all ready before regulators or customers had to ask.