Full Report
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
Analysis Summary
# Incident Report: Amgen Third-Party Cloud Data Breach
## Executive Summary
In July 2026, biotechnology giant Amgen identified unauthorized access to multiple cloud systems operated by third-party service providers. Threat actors successfully exfiltrated proprietary corporate data and Protected Health Information (PHI). While the company has deemed the incident "material" due to the sensitivity of the stolen data, it does not currently anticipate a significant impact on its overall financial condition.
## Incident Details
- **Discovery Date:** July 2026
- **Incident Date:** July 2026 (Ongoing investigation)
- **Affected Organization:** Amgen
- **Sector:** Pharmaceutical / Biotechnology
- **Geography:** California, USA (Global operations)
## Timeline of Events
### Initial Access
- **Date/Time:** July 2026
- **Vector:** Targeted compromise of third-party cloud service providers.
- **Details:** Specific entry methods (e.g., vishing or credential theft) are currently under investigation; however, the breach originated within external cloud environments hosting Amgen data.
### Lateral Movement
- Attackers navigated through multiple disparate cloud systems operated by third-party vendors to identify and aggregate sensitive data repositories.
### Data Exfiltration/Impact
- **Exfiltrated Data:** Proprietary corporate data, Protected Health Information (PHI), and other sensitive information.
- **Pending Investigation:** Potential theft of intellectual property (IP), R&D data, and confidential business information.
### Detection & Response
- **July 2026:** Amgen detected unauthorized activity within the cloud environments.
- **July 29, 2026:** Amgen officially determined the incident to be "material" following an evaluation of the volume and sensitivity of the compromised files.
- **Response:** Activated cybersecurity incident response plan and engaged third-party forensic firms.
## Attack Methodology
*Note: Specific technical details are currently limited as the investigation is ongoing.*
- **Initial Access:** Compromise of third-party cloud service provider environments.
- **Persistence:** Unknown (likely via compromised cloud service accounts).
- **Privilege Escalation:** Information not yet disclosed.
- **Defense Evasion:** Information not yet disclosed.
- **Credential Access:** Potential vishing or SSO account compromise (investigation pending).
- **Discovery:** Enumeration of files stored in cloud-based storage and databases.
- **Lateral Movement:** Pivot between different third-party cloud platforms.
- **Collection:** Aggregation of proprietary files and patient health records.
- **Exfiltration:** Transfer of sensitive data from third-party cloud environments to attacker-controlled infrastructure.
- **Impact:** Unauthorized disclosure of regulated health data and trade secrets.
## Impact Assessment
- **Financial:** Currently assessed as not likely to have a material impact on financial condition/operating results.
- **Data Breach:** Exposure of PHI and proprietary corporate data. Total volume and number of affected individuals are still being determined.
- **Operational:** Activation of incident response protocols and forensic investigations.
- **Reputational:** Potential loss of trust from patients and partners due to the exposure of sensitive medical and research data.
## Indicators of Compromise
- **Network indicators:** No specific IPs or URLs have been disclosed by the organization at this time.
- **File indicators:** Information not yet disclosed.
- **Behavioral indicators:** Unusual data egress patterns from third-party cloud storage buckets; unauthorized access logs from unexpected geographic locations.
## Response Actions
- **Containment measures:** Implementation of security measures to isolate affected cloud environments.
- **Eradication steps:** Hiring of independent forensic experts to purge unauthorized access.
- **Recovery actions:** Ongoing forensic review to determine the full scope of the breach and fulfillment of legal/regulatory notification requirements.
## Lessons Learned
- **Supply Chain Vulnerability:** Even if internal networks are secure, data stored with third-party cloud providers remains a high-value target and a significant point of failure.
- **Materiality Timing:** The transition from discovery to a "materiality" determination requires a rapid assessment of data volume and sensitivity.
- **Cloud Visibility:** Reliance on third parties can complicate the speed of forensic investigations and the visibility of attacker movements.
## Recommendations
- **Third-Party Risk Management (TPRM):** Conduct rigorous security audits of all cloud service providers and enforce strict data encryption standards for data-at-rest.
- **Identity Security:** Implement phishing-resistant Multi-Factor Authentication (MFA) across all corporate and third-party cloud access points to prevent SSO-based attacks.
- **Data Minimization:** Regularly review and purge sensitive patient or R&D data from third-party environments if it is no longer required for active operations.
- **Enhanced Monitoring:** Deploy Cloud Access Security Brokers (CASB) to monitor and alert on anomalous data transfers from third-party platforms.