Amgen Discloses Material Cybersecurity Incident, Says Patient Data Exfiltrated
Amgen Inc. disclosed in a Form 8-K filed July 31 that attackers exfiltrated data, including patient protected health information and proprietary information, from cloud environments hosted by third-party providers. The Thousand Oaks, California drugmaker determined on July 29 that the intrusion constitutes a material cybersecurity incident.
According to the filing, Amgen identified unauthorized activity in the cloud environments in July 2026, activated its cybersecurity response plan, implemented containment measures, and engaged independent forensic experts. The company said it has since learned that some data has been exfiltrated but that it has not identified any impact to its products, manufacturing operations, financial reporting systems, or ability to meet patient needs.
The 8-K was signed by Jonathan P. Graham, Amgen’s executive vice president, general counsel, and secretary. Amgen said it continues to evaluate applicable regulatory and legal notification requirements and will make required notifications based on its findings, including to affected patients. A representative for Amgen declined to comment beyond the filing, Claims Journal reported, republishing a Reuters account of the disclosure.
What the Filing Says About Scope
Amgen described the intrusion as involving data stored in cloud environments hosted by third-party cloud service providers. The filing does not name the providers, identify the threat actor, or specify the number of patients whose information was involved. Nor does it quantify the volume of exfiltrated files beyond stating that the company’s materiality determination was based on “the volume of the files that appear to have been impacted and the potential that the types of information in such files could be sensitive.”
The categories of data Amgen says were exfiltrated include proprietary data, patient protected health information, and “other information.” The company said it is continuing to assess whether patient information, confidential business information, intellectual property, research and development data, or other information may have been accessed, acquired, or exfiltrated. Amgen said the investigation is ongoing and that it will amend the 8-K as further information becomes available.
The company also stated that it believes, as of the date of the filing, that the incident is not reasonably likely to have a material impact on its financial condition or results of operations. That assessment sits alongside the separate determination, under Item 1.05, that the incident itself is material and required disclosure.
Why July 29 Made It a Material Cybersecurity Incident
An Item 1.05 Form 8-K must be filed within four business days of a registrant determining that an incident was material, under rules the U.S. Securities and Exchange Commission adopted on July 26, 2023 requiring registrants to describe the material aspects of the nature, scope, and timing of the incident and its material impact or reasonably likely material impact.
Amgen’s filing tracks the framework’s distinction between materiality of the incident and materiality of its financial effects, treating them as separate questions. The filing anchors the July 29 determination in the volume of affected files and the sensitivity of the data categories rather than in any quantified financial exposure.
The disclosure identifies the incident type, the environment involved, the categories of data exfiltrated, the containment steps taken, and the operational areas the company says have not been affected. Under Item 1.05(a), a registrant that has not yet determined or that lacks certain required information at the time of filing must amend the 8-K when the information becomes available. Amgen expressly reserved the right to do so.
Stryker, Intuitive Surgical, and Novo Nordisk Came First
The Amgen disclosure follows a series of cyber incidents affecting healthcare and life-sciences companies. Claims Journal, in the Reuters account it published August 4, noted that a cyberattack earlier in the year disrupted operations at medical-technology company Stryker Corp., that Intuitive Surgical Inc. subsequently reported a cybersecurity incident, and that Novo Nordisk identified unauthorized access to some IT systems used for its global business.
Amgen said in the 8-K that it takes its obligation to safeguard the privacy and security of its patients’ data seriously and that it will make all required notifications based on its findings. The investigation remains ongoing.
